Microsoft 365 SPF, DKIM and DMARC
Both DKIM selectors, the right CNAME target, and the records Exchange Online needs.
Microsoft 365 needs an SPF TXT record, two DKIM CNAME records, and a DMARC TXT record. The two DKIM records are not optional alternatives: Microsoft alternates between `selector1` and `selector2` when it rotates keys, so if only one exists, DKIM breaks at the first rotation.
Mail from your `*.onmicrosoft.com` initial domain is DKIM signed automatically. Mail from your custom domain is not, until you publish both CNAMEs and enable signing for that domain in the Defender portal.
The records Microsoft 365 needs
TXT · host @
v=spf1 include:spf.protection.outlook.com -all
Microsoft's record for Exchange Online. Add other senders as further includes in the same record.
CNAME · host selector1._domainkey
selector1-<your-domain-with-dashes>._domainkey.<tenant>.<partition>-v1.dkim.mail.microsoft
Newer tenants use the dkim.mail.microsoft target. Older ones use selector1-<domain-with-dashes>._domainkey.<tenant>.onmicrosoft.com. Copy the exact value from the Defender portal or Get-DkimSigningConfig.
CNAME · host selector2._domainkey
selector2-<your-domain-with-dashes>._domainkey.<tenant>.<partition>-v1.dkim.mail.microsoft
Required, not a spare. Microsoft rotates between selector1 and selector2, so both must exist permanently.
TXT · host _dmarc
v=DMARC1; p=none; rua=mailto:<your reporting address>
Start at p=none with reporting, then raise the policy once reports are clean.
MX · host @
<your-domain-key>.mail.protection.outlook.com (priority 0)
Your tenant-specific inbound host, shown in the Microsoft 365 admin centre under Domains.
Values shown with placeholders are account-specific — copy the exact value from Microsoft 365, never from a guide.
What goes wrong
- The CNAME target format changed
- Guides written before the change show `...._domainkey.<tenant>.onmicrosoft.com`. Newer tenants are issued `...._domainkey.<tenant>.<partition>-v1.dkim.mail.microsoft` instead. Never type the target from a guide — read it out of the portal or from `Get-DkimSigningConfig -Identity <domain> | Format-List Selector1CNAME,Selector2CNAME`.
- Your domain name appears with dashes, not dots
- In the target, `contoso.com` becomes `contoso-com`. Copying the dotted form produces a CNAME that resolves to nothing and a `dkim=fail (no key for signature)`.
- Publishing the CNAMEs is not the same as enabling DKIM
- After both records resolve, toggle the domain to Enabled on the DKIM tab of Email authentication settings in the Defender portal. Before that, custom-domain mail is unsigned.
- -all is the documented default here
- Microsoft publishes `-all` rather than `~all`. That is fine once every sender is listed, and a problem the moment a tool sends as your domain without an aligned DKIM signature.
Questions
- What is the SPF record for Microsoft 365?
- `v=spf1 include:spf.protection.outlook.com -all` as a TXT record on your root domain. One record only, with any additional senders added as further includes.
- Why does Microsoft 365 need two DKIM CNAMEs?
- Because key rotation alternates between the `selector1` and `selector2` names. Whichever one is active, the other must already resolve, or the next rotation leaves receivers unable to fetch your key.
- Where do I find my selector1 and selector2 values?
- In the Defender portal under Email authentication settings → DKIM, in the details for your domain; or in Exchange Online PowerShell with `Get-DkimSigningConfig -Identity <domain> | Format-List Selector1CNAME,Selector2CNAME`.
- Does Microsoft 365 sign my mail by default?
- Only for your initial `*.onmicrosoft.com` domain. Custom domains need both CNAMEs published and DKIM signing enabled for that domain.
Fix this from ChatGPT or Claude
MailVakt is an MCP server, so your assistant can run this check itself, read the findings and walk you through the DNS edit. Ask it:
“example.com runs on Microsoft 365. Check SPF, DKIM selector1 and selector2, and DMARC, and tell me what is missing.”
- Claude: Settings → Connectors → Add custom connector, then paste
https://mcp.mailvakt.com/mcp. - Cursor and other MCP clients: add the same address as an MCP server. Setup details.
Checks are free and need no account. Sign in only to collect DMARC reports for a domain.