Outlook / Microsoft 365: SPF, DKIM & DMARC Setup Guide
Microsoft 365 has its own reputation systems (SNDS, Smart Network Data Services) and its own blacklist. Getting SPF, DKIM, and DMARC right is essential for reliable delivery to Outlook and Hotmail users.
1SPF Record Setup
Recommended SPF record for Microsoft 365:
v=spf1 include:spf.protection.outlook.com ~allMicrosoft's SPF include covers all Exchange Online sending IPs. If you also use other services (e.g., Mailchimp, Salesforce), add their includes before the ~all mechanism.
Step-by-step setup:
- 1Log in to your domain registrar or DNS provider
- 2Find TXT records for your root domain (@)
- 3Add or update to: v=spf1 include:spf.protection.outlook.com ~all
- 4If you send from other services, include them too (only one SPF record allowed)
- 5Save and wait 24–48 hours for propagation
- 6Verify in Microsoft 365 Admin Center under Domains
2DKIM Setup
Example DKIM record location:
selector1._domainkey.yourdomain.comMicrosoft 365 uses two DKIM selectors: selector1 and selector2. Both need to be published. Microsoft rotates between them automatically. You'll add two CNAME records (not TXT records) pointing to Microsoft's key servers.
Step-by-step setup:
- 1In Microsoft 365 Admin Center, go to Settings → Domains → select your domain
- 2Go to Security section or use the Defender portal (security.microsoft.com)
- 3Under Email & Collaboration → Policies → DKIM, select your domain
- 4Click Enable — Microsoft will show you two CNAME records to add
- 5Add both CNAME records to your DNS: selector1._domainkey and selector2._domainkey
- 6Return to the portal and enable DKIM signing
- 7Verify with our DKIM checker (look for selector1 and selector2)
3DMARC Policy
Recommended DMARC record:
v=DMARC1; p=quarantine; rua=mailto:dmarc@yourdomain.com; pct=100Add as a TXT record at: _dmarc.yourdomain.com
Microsoft checks DMARC on inbound email and recommends p=reject for maximum protection. Microsoft SNDS (Smart Network Data Services) is a separate IP reputation service — register your sending IPs at postmaster.live.com.
Common Microsoft 365 Deliverability Issues
Emails blocked by Microsoft with error 550 5.7.1
Your IP is likely on Microsoft's blocklist. Register at https://sender.office.com to submit a delisting request. Ensure SPF and DKIM are correctly configured first.
DKIM CNAME records not resolving
Microsoft 365 DKIM uses CNAME records, not TXT. Make sure you're adding CNAME entries. Allow 24–48 hours for propagation before enabling in the portal.
Mail going to Junk folder in Outlook
Check that SPF, DKIM, and DMARC all pass. Verify your sending IP isn't listed in SNDS. Consider registering with Microsoft's JMRP (Junk Mail Reporting Program).
550 5.7.520 Message rejected due to content filtering
The email content triggered spam filters. Review for spam trigger words, excessive links, or missing unsubscribe links. Test with our email spoofing test to verify authentication passes.
Is Your Microsoft 365 Domain Blacklisted?
Authentication passing is necessary — but not sufficient. Check if your sending domain or IP is on any of 60 blacklists. Free, instant, no signup.
Check Your Domain FreeChecks all 60 blacklists + SPF, DKIM, DMARC, MX in under 10 seconds