100% Client-Side EngineZero data storage • No email signup required • 2026 Google & Yahoo Bulk Sender Compliant
Business Email Suite 2026 Google & Yahoo Compliant

Microsoft 365 / Exchange Online SPF & DMARC Setup Guide

Microsoft 365 uses spf.protection.outlook.com to authenticate mail routed through Exchange Online Protection (EOP). Microsoft flattens its IP subnets so this include only consumes a single DNS lookup.

Business Email SuiteRFC 7208 & RFC 7489 Validated

Microsoft 365 / Exchange Online DNS Preset Generator

Enter your domain below to customize the exact SPF and DMARC TXT records required for Microsoft 365 / Exchange Online.

RFC 7208 DNS Lookup Cost1 of 10 Lookups

1 direct include query (contains flat IP address blocks). Microsoft 365 consumes only 1 DNS lookup, leaving 9 lookups for your other marketing or transactional providers.

Lookup Budget1/10
RECORD 1: SPFHost: @ (or apex domain)Type: TXT
v=spf1 include:spf.protection.outlook.com ~all

⚠️ Important: If your domain already publishes an existing SPF record, merge include:spf.protection.outlook.com into that record. Never publish two separate SPF records.

RECORD 2: DMARCHost: _dmarc (or _dmarc.example.com)Type: TXT
v=DMARC1; p=quarantine; rua=mailto:dmarc-reports@example.com; pct=100; adkim=r; aspf=r

This policy enforces p=quarantine (suspicious emails routed to spam) and directs daily XML compliance reports to dmarc-reports@example.com.

Live DNS Propagation Check for example.com

Query Cloudflare DNS-over-HTTPS in real-time to check if your domain already publishes valid records.

Using Microsoft 365 / Exchange Online alongside other platforms?Open Multi-Provider SPF Merger & Lookup Calculator
Step-by-Step Instructions

How to configure Microsoft 365 / Exchange Online in your DNS

Follow these 4 straightforward steps to publish your authentication records on Cloudflare, GoDaddy, Namecheap, or AWS Route 53.

1

Locate Your Current SPF Record

Check your DNS zone for any existing TXT record starting with v=spf1. If none exists, prepare to create a new TXT record at host @.

2

Add Microsoft 365 Include

Insert include:spf.protection.outlook.com before the final all qualifier.

v=spf1 include:spf.protection.outlook.com ~all
3

Enable Dual CNAME DKIM Keys

In the Microsoft Defender portal, enable DKIM for your custom domain by publishing two CNAME records: selector1._domainkey and selector2._domainkey.

4

Publish DMARC Record

Create a TXT record with host _dmarc specifying your policy and aggregate report mailbox.

v=DMARC1; p=quarantine; rua=mailto:dmarc-reports@yourdomain.com; pct=100
Technical Q&A

Frequently Asked Questions for Microsoft 365 / Exchange Online

Technical answers regarding lookup limits, multiple records, and delivery errors.

Does Microsoft 365 use -all or ~all in SPF?▼
Microsoft officially recommends ~all (SoftFail) to accommodate complex routing, mobile clients, and third-party relay systems without causing immediate hard bounces.
How many DNS lookups does Microsoft 365 require?▼
spf.protection.outlook.com requires exactly 1 DNS lookup. Unlike Google, Microsoft does not recurse into nested sub-includes.
Why does Microsoft 365 need two DKIM records?▼
Microsoft uses dual rotating keys (selector1 and selector2) so their security infrastructure can rotate cryptographic keys automatically without email downtime.

Common Providers Used with Microsoft 365 / Exchange Online

Send marketing and transactional emails alongside your corporate inbox.

View All 50+ Guides
Full Email Deliverability Suite

Need to combine multiple providers into one SPF record?

Our full in-browser engine merges SPF records, calculates RFC 7208 lookups in real-time, and generates custom DMARC policies.