You want to set up DMARC for your Microsoft 365 domain, but there is no custom-domain publishing option in the Microsoft 365 admin center. The setup starts with SPF and DKIM, followed by a DMARC record at your DNS host. Follow the sequence below to publish a monitoring policy, check a real outgoing message, and move to enforcement after fixing legitimate-sender failures.
Get DNS access and configure SPF first
These steps apply to custom domains using Exchange Online, such as your-domain.tld. You need access to the domain’s authoritative DNS host and an authorized Microsoft 365 administrator account.
Open the account at the DNS provider that manages your domain’s records. Microsoft 365 has no custom-domain DMARC publishing portal or PowerShell cmdlet.
Create or update the root-domain SPF TXT record, usually named @. For a domain sending exclusively through Microsoft’s commercial Microsoft 365 service, use v=spf1 include:spf.protection.outlook.com -all.
Incorporate other legitimate sending services into that same SPF record. Keep one SPF record, using the documented values for your senders and, where applicable, your sovereign-cloud configuration.
For Microsoft 365 purchased through GoDaddy, use the SPF value specified for your GoDaddy email configuration. GoDaddy adds SPF automatically when your domain, DNS, and email are in the same GoDaddy account; its SPF instructions include include:secureserver.net.
If you only have mailbox access, ask your domain or tenant administrator to complete the setup. Microsoft 365 Personal and Family Outlook.com accounts are a separate product, and the Exchange Online admin paths below do not apply to them.
Enable DKIM in Microsoft Defender
Get your domain’s DKIM records and enable signing in Microsoft Defender; a paid Defender plan is not required.
- 1.Open security.microsoft.com and go to Email & collaboration > Policies & rules > Threat policies > Email authentication settings > DKIM. Microsoft moved these protection features from the classic Exchange admin center to Defender, so the old Protection > DKIM route is no longer a current setup method.
- 2.For an unconfigured domain, change Toggle from Disabled to Enabled. Dismiss the Client error message with OK.
- 3.Select your domain, open Publish CNAMEs, and select Copy.
- 4.Publish both CNAME records at your DNS host using the names and targets Microsoft supplies. In Cloudflare, set Proxy status to DNS only for both records and make sure CNAME flattening isn’t applied to them; a proxied DKIM CNAME resolves to Cloudflare’s addresses instead of Microsoft’s target, and DKIM verification fails.
- 5.Return to the domain’s DKIM settings, enable Sign messages for this domain with DKIM signatures, and select OK.
- 6.Confirm the status reads Signing DKIM signatures for this domain.
If you have Microsoft 365 from GoDaddy with Advanced Email Security from Proofpoint, also set up DKIM in Advanced Email Security. Sign in to Advanced Email Security, go to Administration > Account Management > Domains, select your domain, and choose Configure DKIM > Create New DKIM Signing Key. Publish the displayed host and value as a TXT record at your DNS host, then return to Domains, select Verify DKIM Keypair, and choose More options > Verify Key.
Publish one DMARC record for your domain
Check your DNS records for an existing policy at _dmarc.your-domain.tld, replacing your-domain.tld with your domain.
Open the existing policy for editing, or create a TXT record at that name if none exists.
Enter v=DMARC1; p=none; rua=mailto:[email protected] as the record value, replacing [email protected] with your aggregate-report recipient’s address.
Save the record using your provider’s control below, keeping only one DMARC policy at that name.
Tip: Start an active sending domain with p=none for monitoring, then tighten the policy after reviewing reports and fixing legitimate-sender failures.
Enter the right DNS fields for your provider
At GoDaddy, open Domain Portfolio, select your domain under Domain Name, and open DNS; inspect any existing DMARC record first because GoDaddy automatically adds DMARC to new domains purchased starting April 2025, although SPF and DKIM still need configuration. For a missing policy, select Add New Record and set Type to TXT, Name to _dmarc, Value to your policy, and TTL to Default. Select Save.
In Cloudflare, select your domain and open DNS > Records > Add record. Set Type to TXT, Name to _dmarc, and Content to your policy, choose a TTL, then select Save. For an existing policy, select Edit on its record and then Save.
For Namecheap BasicDNS, PremiumDNS, or FreeDNS, open Domain List > Manage beside your domain > Advanced DNS > Add new record. Choose TXT Record, enter _dmarc in Host without appending your domain, enter your policy in Value, and select Save all changes. Namecheap Web Hosting DNS uses cPanel instead.
For a Squarespace-managed domain, select it in the domains dashboard and open DNS > DNS Settings > Custom Records > Add record. Set Type to TXT, Name to _dmarc, and Text to your policy, then select Save; edit an existing policy instead of adding a duplicate. Domains connected through DNS Connect use their external DNS provider.
Check publication and a real outgoing message
These checks pinpoint publication and test-message authentication problems.
Run nslookup -type=TXT _dmarc.your-domain.tld on a system with nslookup, substituting your domain.
Confirm the result contains your intended policy and only one DMARC policy at that name. This checks DNS publication, not whether your email passes authentication.
Send a message from your Microsoft 365 domain to an external mailbox.
In new Outlook, Outlook on the web, or Outlook.com, open the received message.
Select More actions > View > View message details.
For classic Outlook for Windows, double-click the received message instead.
Open File > Properties.
Inspect Internet headers.
Look in Authentication-Results for dmarc=pass and an aligned SPF or DKIM result. At least one aligned SPF or DKIM result must pass.
For a Gmail test mailbox, open the received message in a browser.
Select More beside Reply.
Choose Show original.
Inspect the authentication results and headers.
Move to enforcement after monitoring
Once your policy is published and aggregate reports are arriving, use them to identify legitimate senders with authentication failures. Fix those failures before tightening the policy.
Edit your existing DMARC TXT value from p=none to p=quarantine, keeping your reporting address.
Save the updated record using your DNS provider’s save control.
Review the aggregate reports again.
Resolve legitimate-sender failures at this stage.
Change p=quarantine to p=reject after completing that review.
Save the change to the existing record instead of adding another policy.
A parent-domain DMARC policy covers subdomains without their own policy. To give marketing.your-domain.tld a separate policy, publish it at _dmarc.marketing.your-domain.tld.
Protect an onmicrosoft.com domain separately
Your tenant’s onmicrosoft.com domain uses a different publishing route. A tenant administrator adds its DMARC record in the Microsoft 365 admin center.
Open admin.microsoft.com and go to Show All > Settings > Domains.
Select your onmicrosoft.com domain.
Open DNS records > + Add record.
Set Type to TXT (Text).
Enter _dmarc in TXT name.
Enter v=DMARC1; p=reject; rua=mailto:[email protected] in TXT value, replacing the reporting address with your own.
Select Save.
If this route fails, open Help & Support in the Microsoft 365 admin center and enter your question in Support Assistant. Select Contact support for further help. Publishing a custom-domain policy still requires access to its DNS provider.
Frequently Asked Questions
Does Microsoft 365 Domain Connect publish DMARC automatically?
No. Domain Connect can publish SPF and DKIM prerequisite records at supported registrars, but you must publish DMARC separately.
Does enabling incoming DMARC enforcement publish my domain’s policy?
No. The Honor DMARC record policy when the message is detected as spoof setting in Microsoft Defender controls how incoming messages are handled. Your sending domain’s DMARC policy still needs to be published in DNS.
What DMARC policy should I use for a domain that never sends email?
Verify a non-sending SPF configuration, then ask your DNS provider to publish v=DMARC1; p=reject as a TXT policy at _dmarc. You can also add a reporting address.
Will Microsoft send forensic reports if I add ruf to my policy?
No. Microsoft does not send forensic reports, even when ruf is present. Use rua to specify an aggregate-report recipient.