DMARC for Microsoft 365
Microsoft 365 can sign outbound mail with DKIM and align with SPF when you use the correct outbound routing. DMARC ties those signals together so receivers know it is really your tenant sending as your domain.
- Enable and confirm DKIM for your domain inside the Microsoft Defender portal or classic Exchange admin paths—Microsoft publishes two selector CNAMEs you must add at DNS.
- Keep SPF accurate for mail that leaves Microsoft's infrastructure, including any third-party senders that use your domain in the
Fromheader. - Publish DMARC with
p=noneand aggregate reporting to learn which senders pass or fail before you tighten policy. - Use report data to fix forwarded mail, marketing tools, and shadow IT senders—then move toward
quarantineandrejectwhen failures are under control.
Our scanner checks MX-detected providers and surfaces copy-ready DNS fixes.
Scan your domain