Reviewed by: QuickDMARC Security Team · Email Authentication Specialists ·

Microsoft 365 DMARC

Microsoft 365 does not host your organizational DMARC policy. You publish _dmarc in DNS, align Exchange Online SPF/DKIM, then monitor aggregate reports before enforcement.

What to configure

Publish DMARC with rua, enable M365 DKIM, keep include:spf.protection.outlook.com accurate, and authorize every SaaS that sends as your domain.

v=DMARC1; p=none; rua=mailto:[email protected]
; ensure M365 DKIM enabled + SPF include present

Common M365 pitfalls

Assuming the Microsoft 365 admin center publishes DMARC; forgetting printer/scanner SMTP; adding too many ESP includes; disabling DKIM after domain changes.

Validation steps

Send external test messages, inspect Authentication-Results, run DMARC/SPF/DKIM checkers, and confirm aggregate reports arrive.

How QuickDMARC helps

QuickDMARC monitors M365 domains, highlights unaligned SaaS, and supports Managed DMARC for policy changes without ticket ping-pong.

Frequently asked questions

Does Microsoft host my DMARC record?

No. You publish _dmarc at your DNS provider.

Is SPF include enough?

No. Enable DKIM and publish DMARC with reporting.

Deep-dive setup?

See the Microsoft 365 DMARC setup guide.

Related resources