Skip to main content
Protect your domain reputation today
SimpleDMARC
Office 365← All how-tos

How to Set Up DMARC for Office 365 | SimpleDMARC

Step-by-step DMARC setup for Office 365 — including multi-domain tenants and hybrid Exchange. Generate a monitor-mode record, publish DNS, verify, then enforce safely.

SimpleDMARC Team

Last updated August 12, 2026

Why Office 365 Needs DMARC

If someone can send mail that looks like it came from your domain, they will, eventually. DMARC is what stops that: it tells receiving mail servers what to do with messages that fail SPF or DKIM, and it hands you reports showing exactly who's sending as your domain — including services you forgot you'd connected.

Office 365 setups get complicated fast. Most tenants aren't just Exchange Online — there's usually a CRM, a marketing tool, sometimes a helpdesk platform, and in larger organizations, an on-premises Exchange server that never quite got decommissioned. If your tenant handles more than one domain (a lot do — a main brand plus an acquired product or a regional site), each of those needs its own record. This guide covers the straightforward path and the parts that trip people up on real tenants.

Start with p=none. You want to see what's actually sending mail before you risk blocking any of it.

Step 1Generating Your DMARC Record

Create a TXT record at _dmarc.yourdomain.com in monitor mode. Swap in your real domain and a reporting address you control.

DNS / record
v=DMARC1; p=none; rua=mailto:dmarc-reports@yourdomain.com; ruf=mailto:dmarc-reports@yourdomain.com; fo=1; adkim=r; aspf=r; pct=100

What each part is doing:

  • p=none — monitor only, nothing gets blocked
  • rua / ruf — where your aggregate and forensic reports land
  • adkim=r / aspf=r — relaxed alignment, which you want while you're still figuring out what's sending mail

If your tenant has more than one accepted domain sending real mail, repeat this for each one. A DMARC record on company.com protects nothing on companybrand.io — DMARC doesn't inherit across domains in the same tenant, even though it feels like it should.

Step 2Configure SPF for Office 365

Microsoft needs to be authorized in your SPF record:

DNS / record
v=spf1 include:spf.protection.outlook.com ~all

Almost nobody's tenant sends through Exchange Online alone. If you've got Mailchimp, Salesforce, or anything else sending as your domain, add it:

DNS / record
v=spf1 include:spf.protection.outlook.com include:servers.mcsv.net ~all

Never publish two SPF records on the same host — merge them into one. And if a secondary domain in your tenant only sends through Exchange Online with nothing else attached, don't just copy your primary domain's SPF record onto it. Check what that specific domain actually sends before assuming.

Step 3Publish DMARC and Enable DKIM

DMARC lives in DNS, not in the Microsoft 365 admin center — add a TXT record with your DNS host the same way you would any other record. Host: _dmarc (some panels want the full _dmarc.yourdomain.com — check which one applies).

DKIM is where Office 365 gets genuinely confusing, because Microsoft has moved this setting around over the years. Look in the Microsoft 365 Defender portal first — Email & collaboration → Policies & rules → Threat policies → Email authentication settings. Some older tenants still reference DKIM through the legacy Exchange admin center instead, so if you don't see it in Defender, check there.

Generate the DKIM key, publish the two CNAME records Microsoft gives you, then go back and actually turn signing on. Publishing the records isn't enough — there's a separate toggle, and it's easy to miss.

Step 4Wait for Enforcement (Monitor First)

Give it one to two weeks of normal sending before touching your policy. Watch for:

  • Sources you don't recognize failing authentication
  • Legitimate tools that need adding to SPF or their own DKIM setup
  • What percentage of your mail is already passing cleanly

If you're running hybrid Exchange, expect on-premises mail to show up failing DKIM in reports even when it's completely legitimate — that's the SPF-only alignment mentioned above playing out in the data. Once you're confident, move to p=quarantine, then eventually p=reject, by updating the same TXT record. On multi-domain tenants, move each domain up independently as its reports look clean — there's no reason to wait for the slowest one.

Step 5Verify Your Setup

  • Look up _dmarc.yourdomain.com with the DMARC Checker — check every accepted domain separately, not just your primary one
  • Confirm SPF with the SPF Checker
  • Send a real test message to an external inbox and look at the authentication results

Once DMARC, SPF, and DKIM line up, you're in position to tighten policy — and if brand logos in supporting inboxes matter to you, BIMI is worth planning once enforcement is solid.

Frequently asked questions

Where do I publish the DMARC record for Office 365?
In DNS, at whatever host manages your domain. The Microsoft 365 admin center doesn't store the DMARC TXT record itself — it only handles DKIM signing.
Do I need a separate DMARC record for every domain in my tenant?
Yes. DMARC works per domain, not per tenant. Each accepted domain sending real mail needs its own record.
My hybrid Exchange mail keeps failing DKIM in reports. Is that a problem?
Not on its own. On-premises Exchange doesn't sign with Microsoft 365's keys, so DKIM failure there is expected. Check that SPF passes instead.
I can't find DKIM settings in the Defender portal. Where else should I look?
Some tenants, particularly older ones, still have DKIM configured through the legacy Exchange admin center rather than Defender.
Should I start with p=reject?
No. Start with `p=none`, watch the reports, fix what's failing, then move up gradually.
Can some domains in my tenant be at p=reject while others stay at p=none?
Yes — this is normal on tenants with multiple domains. Enforce each one as it's ready rather than waiting for all of them together.

Protect your domain with SimpleDMARC

Monitor DMARC reports, catch spoofing early, and move from p=none to enforcement with confidence.

How to Set Up DMARC for Office 365 | SimpleDMARC