Microsoft 365: check SPF, DKIM and DMARC
Secure custom sending domains in Exchange Online and account for additional sending services.
Administrator checklist
- Inventory services using your domain: Exchange Online, applications, ticket systems and external senders. MX primarily describes inbound delivery.
- Use the SPF check to inspect the existing policy. Do not publish a second SPF record for additional services; consolidate required sources in one coordinated policy.
- Read current DKIM CNAME values from your Microsoft 365 tenant. Use those exact values rather than guessing targets from examples or a tenant name. Then enable DKIM for the custom domain.
- Check known selectors and representative messages from every sending path. A published key alone does not show whether Exchange Online signs every relevant message with the intended domain.
- Publish an appropriate DMARC policy and monitor reports. Tightening enforcement requires reviewing legitimate sources and alignment. The Outlook.com recipient check additionally considers your declared volume.
This guide covers sending configuration. It grants no tenant access and does not replace checking individual mail paths. Microsoft or Google sign-in proves neither domain ownership nor configuration.
Sources reviewed: 2026-09-10
Official source · Microsoft 365 / Exchange Online