cloud.microsoft
Good, with 3 things to fix
cloud.microsoft scored 76/100 (grade B). The main issues are DMARC alignment: DKIM alignment is unlikely under adkim=s and DKIM key revoked, plus 1 more.
Checked 2026-10-04 02:02 UTC · fresh check
All checks
MXCan servers find your inbox?Mail relies on implicit A recordNeeds attention
- Warning: Mail relies on implicit A record
cloud.microsoft has no MX records, so senders fall back to its A/AAAA address (RFC 5321 implicit MX). Publish an explicit MX record, or a null MX ("0 .") if the domain should not receive mail.
SPFWho may send as you?No issues foundPass
Nothing to report.
DKIMAre your emails signed?DKIM key revokedNeeds attention
- Warning: DKIM key revoked
google, selector1, selector2, k1, k2, k3, s1, s2, mail, default, dkim, smtp, mandrill, pm, pm-bounces, mg, mailo, krs, email, sendinblue, brevo, hs1, hs2, amazonses, ses, zendesk1, zendesk2, fd, fd2, protonmail, protonmail2, protonmail3, zoho, everlytickey1, everlytickey2, sig1, cm, mxvault, turbo-smtp, sparkpost, scph0123, kl, kl2, resend, intercom, cf2024-1, cf-bounce publishes an empty p= tag, so any mail still signed with that selector fails DKIM. That is correct after a key rotation; otherwise publish the current key or stop signing with this selector.
DMARCWhat happens to fakes?DMARC uses strict alignmentInfo
- Info: DMARC uses strict alignment
With adkim=s or aspf=s the DKIM d= domain or the bounce domain must equal the From domain exactly; a subdomain is not enough. Third-party senders that sign or bounce from a subdomain (or their own domain) will then fail DMARC unless they are configured to use your exact domain.
AlignmentDoes it match your From?DKIM alignment is unlikely under adkim=sNeeds attention
- Warning: DKIM alignment is unlikely under adkim=s
This is a heuristic. No DKIM key was found at cloud.microsoft under the selectors we probed, and adkim=s requires the signing d= domain to equal cloud.microsoft exactly. If your mail is signed with a provider's domain or a subdomain, DKIM will not align. A key may exist under a selector we did not try; send a test message to confirm.
- Info: SPF alignment is unknown
The SPF record of cloud.microsoft authorizes no sender (no +ip4, +ip6, +a, +mx, +exists or +ptr term, include of a record that has one, or +all before all), so SPF never passes and cannot align. That is correct for a domain that sends no mail; otherwise DMARC depends on DKIM alone.
BIMICan inboxes show your logo?No BIMI recordInfo
- Info: No BIMI record
No BIMI record at default._bimi.cloud.microsoft. BIMI is optional: it shows your logo next to your mail in supporting inboxes once DMARC is enforced.
How to fix this
MTA-STSIs mail to you encrypted?No MTA-STS recordInfo
- Info: No MTA-STS record
No MTA-STS record at _mta-sts.cloud.microsoft. MTA-STS (RFC 8461) makes sending servers require TLS and a valid certificate when delivering to you, which blocks downgrade attacks.
TLS-RPTWill you hear about failures?No TLS-RPT recordInfo
- Info: No TLS-RPT record
No TLS reporting record at _smtp._tls.cloud.microsoft. TLS-RPT (RFC 8460) tells senders where to send daily reports about failed encrypted deliveries to you.
How to fix this
How to fix it
Set up a TLS report addressinstruction
Sending servers will report TLS failures when delivering to cloud.microsoft, which you need before enforcing MTA-STS. The address must accept TLS reports; a DMARC report address does not necessarily do so.
Applies to: _smtp._tls.cloud.microsoft
- Pick an address that will receive TLS reports: a mailbox you read (for example tls-reports@cloud.microsoft, created first) or a TLS reporting service. 2. Publish a TXT record at _smtp._tls.cloud.microsoft with the value v=TLSRPTv1; rua=mailto:<that address>.
Prepare BIMIinstruction
BIMI shows your logo next to messages in supporting inboxes, but only for mail that passes DMARC under an enforced policy.
Applies to: default._bimi.cloud.microsoft
- Enforce DMARC first: p=quarantine or p=reject at 100% (no pct below 100). 2. Convert your logo to an SVG Tiny PS file and host it over HTTPS, for example https://cloud.microsoft/bimi/logo.svg. 3. For Gmail and Apple Mail, obtain a VMC or CMC certificate for the logo. 4. Publish a TXT record at default._bimi.cloud.microsoft with v=BIMI1, l= set to the logo URL and a= set to the certificate URL.