How to Set Up DMARC for Microsoft 365
To set up DMARC for Microsoft 365, publish v=spf1 include:spf.protection.outlook.com -all as your SPF record, create the two DKIM CNAME records (selector1._domainkey and selector2._domainkey) shown in the Microsoft Defender portal and turn on DKIM signing, then add a DMARC TXT record at _dmarc.yourdomain.com starting with p=none. Here is each step, with the exact portal paths.
By Stephen Williams · Updated
Records you'll create
| Record | Type | Host / name | Value |
|---|---|---|---|
| SPF | TXT | @ (root domain) | v=spf1 include:spf.protection.outlook.com -all |
| DKIM | CNAME | selector1._domainkey | Value shown in the Defender portal |
| DKIM | CNAME | selector2._domainkey | Value shown in the Defender portal |
| DMARC | TXT | _dmarc | v=DMARC1; p=none; rua=mailto:dmarc-reports@example.com |
These are for Microsoft 365 commercial and GCC tenants. GCC High, DoD and Microsoft 365 operated by 21Vianet use different SPF includes; check Microsoft's SPF article for those clouds.
Step 1: Publish the SPF record
If Microsoft 365 is the only service that sends email for your domain, publish:
v=spf1 include:spf.protection.outlook.com -allMicrosoft recommends -all (hard fail) for Microsoft 365 domains because DKIM and DMARC are configured too. If other services or on-premises servers send as your domain, add them to the same record; a domain can have only one SPF record and must stay within 10 DNS lookups:
v=spf1 ip4:192.0.2.10 include:spf.protection.outlook.com include:servers.example.net -allMicrosoft advises against flattening spf.protection.outlook.com into IP addresses because its sending IPs change. Build and test your record with the SPF record generator and SPF checker.
Step 2: Turn on DKIM signing with your domain
Microsoft 365 signs mail with your custom domain only after you publish two CNAME records and enable signing. The host names are always selector1._domainkey and selector2._domainkey; the values are specific to your tenant.
CNAME value formats
For custom domains added since May 2025, Microsoft uses this format, where the letter before -v1 (for example n or r) is assigned by Microsoft:
selector1._domainkey CNAME selector1-contoso-com._domainkey.contoso.n-v1.dkim.mail.microsoft
selector2._domainkey CNAME selector2-contoso-com._domainkey.contoso.n-v1.dkim.mail.microsoftDomains that were already set up keep the older format:
selector1._domainkey CNAME selector1-contoso-com._domainkey.contoso.onmicrosoft.com
selector2._domainkey CNAME selector2-contoso-com._domainkey.contoso.onmicrosoft.comEnable DKIM in the Microsoft Defender portal
- Go to security.microsoft.com › Email & collaboration › Policies & rules › Threat policies › Email authentication settings and open the DKIM tab.
- Select your custom domain. If its status is NoDKIMKeys, try to switch the toggle to Enabled: Microsoft shows an error containing the CNAME values and creates the keys, and the status changes to CnameMissing.
- Open the domain's details flyout and copy the two values in the Publish CNAMEs section.
- Create both CNAME records at your DNS host. Microsoft can take a few minutes or longer to detect them.
- Return to the details flyout and turn on Sign messages for this domain with DKIM signatures.
If you create the signing configuration in PowerShell with New-DkimSigningConfig, the default key size is 1024 bits; pass -KeySize 2048 for a stronger key. Verify the published records with the DKIM checker using the selector selector1.
Step 3: Publish the DMARC record
Microsoft 365 has no portal setting for DMARC on custom domains; create the TXT record at your DNS host after SPF and DKIM are working:
v=DMARC1; p=none; rua=mailto:dmarc-reports@example.comMicrosoft's recommended rollout is to start at p=none, move to p=quarantine, then p=reject, monitoring reports at each stage and starting with lower-volume subdomains before the parent domain. Our DMARC policy guide covers the same plan in more detail, and the DMARC record generator builds the record for each stage.
The onmicrosoft.com domain
Microsoft manages SPF and DKIM for your initial *.onmicrosoft.com domain, but its DMARC record is added in the Microsoft 365 admin center: Settings › Domains, select the onmicrosoft.com domain, open DNS records, and add a TXT record named _dmarc. If you don't send mail from that domain, Microsoft recommends:
v=DMARC1; p=rejectVerify and troubleshoot
Send a message to an external mailbox and inspect the Authentication-Results header. You want spf=pass, dkim=pass with header.d= set to your domain, and dmarc=pass. Then confirm the record with the DMARC checker.
- CnameMissing persists: check that your DNS host didn't append the zone name twice (
selector1._domainkey.contoso.com.contoso.com), and that a subdomain's selector host includes the subdomain (for exampleselector1._domainkey.mail). - DKIM passes but DMARC fails: the message was signed with a domain that doesn't align, often
contoso.onmicrosoft.combefore custom DKIM was enabled, or a third-party service signing with its own domain. - SPF PermError: more than one SPF record or more than 10 DNS lookups.
Sources
Frequently asked questions
Why does Microsoft 365 need two DKIM CNAME records?
Microsoft 365 publishes two selectors, selector1 and selector2, so it can rotate DKIM keys without downtime. Only one selector signs mail at a time; after a rotation, which takes four days to take effect, the other one is used.
Which DKIM CNAME format should I use?
Always copy the exact values shown in the Defender portal or by Get-DkimSigningConfig. Custom domains added since May 2025 use targets ending in dkim.mail.microsoft, while existing domains keep the older targets ending in onmicrosoft.com, and the two formats can't be mixed for the same selector.
Do I need DMARC for my onmicrosoft.com domain?
Microsoft already manages SPF and DKIM for the initial onmicrosoft.com domain, but you add its DMARC record yourself in the Microsoft 365 admin center under Settings, Domains. If you don't send email from that domain, Microsoft recommends v=DMARC1; p=reject.
Does Microsoft 365 send DMARC reports?
Microsoft 365 sends DMARC aggregate reports to domains that publish a valid rua address, as long as the receiving domain's MX record points directly to Microsoft 365. It does not send DMARC failure (ruf) reports.