How to configure Microsoft 365 / Exchange Online in your DNS
Follow these 4 straightforward steps to publish your authentication records on Cloudflare, GoDaddy, Namecheap, or AWS Route 53.
Locate Your Current SPF Record
Check your DNS zone for any existing TXT record starting with v=spf1. If none exists, prepare to create a new TXT record at host @.
Add Microsoft 365 Include
Insert include:spf.protection.outlook.com before the final all qualifier.
v=spf1 include:spf.protection.outlook.com ~allEnable Dual CNAME DKIM Keys
In the Microsoft Defender portal, enable DKIM for your custom domain by publishing two CNAME records: selector1._domainkey and selector2._domainkey.
Publish DMARC Record
Create a TXT record with host _dmarc specifying your policy and aggregate report mailbox.
v=DMARC1; p=quarantine; rua=mailto:dmarc-reports@yourdomain.com; pct=100Frequently Asked Questions for Microsoft 365 / Exchange Online
Technical answers regarding lookup limits, multiple records, and delivery errors.
Does Microsoft 365 use -all or ~all in SPF?▼
How many DNS lookups does Microsoft 365 require?▼
Why does Microsoft 365 need two DKIM records?▼
Common Providers Used with Microsoft 365 / Exchange Online
Send marketing and transactional emails alongside your corporate inbox.
Google Workspace (Gmail)
Official Business Gmail & Google Cloud Email
Twilio SendGrid
High-Volume Transactional & Marketing Email API
Amazon SES (Simple Email Service)
Scalable AWS Cloud Infrastructure for Transactional Email
Zoho Mail
Secure Business Email & Productivity Suite for Teams
Need to combine multiple providers into one SPF record?
Our full in-browser engine merges SPF records, calculates RFC 7208 lookups in real-time, and generates custom DMARC policies.