Email Marketing & Automation

How To Set Up Email Authentication with Microsoft Office (SPF, DKIM, DMARC)

We’re seeing more and more deliverability issues with clients these days and too many companies don’t have basic email authentication set up with their office email and email marketing service providers. The most recent was an e-commerce company we’re working with that sends their support messages out of Microsoft Exchange Server.

This is important because the client’s customer support emails are using this mail exchange and then routed through their support ticketing system. So, it’s essential that we set up Email Authentication so that those emails don’t get inadvertently rejected.

When you first set up Microsoft Office on your domain, Microsoft has a nice integration with most Domain Registration servers where they automatically set up all the necessary mail exchange (MX) records as well as a Sender Policy Framework (SPF) record for your Office email. An SPF record with Microsoft sending your office email is a text record (TXT) in your domain registrar that looks like this:

v=spf1 include:spf.protection.outlook.com -all

SPF is an older technology, though, and email authentication has advanced with Domain-based Message Authentication, Reporting and Conformance (DMARC) technology where it’s less likely to have your domain spoofed by an email spammer. DMARC provides the methodology to set how strict you want internet service providers (ISP) to validate your sending information and provides a public key (RSA) to verify your domain with the service provider, in this case, Microsoft.

Steps to setup DKIM in Office 365

While many ISPs like Google Workspace provide you with 2 TXT records to setup, Microsoft does it a little bit differently. They often provide you with 2 CNAME records where any authentication is deferred to their servers for the lookup and authentication. This approach is becoming pretty common in the industry… especially with email service providers and DMARC-as-a-service providers.

  1. Publish two CNAME records:
CNAME: selector1._domainkey 
VALUE: selector1-{your sending domain}._domainkey.{your office subdomain}.onmicrosoft.com
TTL: 3600

CNAME: selector2._domainkey
VALUE: selector2-{your sending domain}._domainkey.{your office subdomain}.onmicrosoft.com
TTL: 3600

Of course, you need to update your sending domain and your office subdomain respectively in the example above.

  1. Create your DKIM Keys in your Microsoft 365 Defender, Microsoft’s administration panel for their clients to manage their security, policies, and permissions. You’ll find this in Policies & rules > Threat policies > Anti-spam policies.
dkim keys microsoft 365 defender
  1. Once you have created your DKIM Keys, then you’ll need to enable Sign messages for this domain with DKIM signatures. One note on this is that it may take hours or even days for this to validate since domain records are cached.
  2. Once updated, you can run your DKIM tests to ensure they’re properly working.

What About Email Authentication adn Deliverability Reporting?

With DKIM, you typically set up a capture email address to have any reports sent to you on deliverability. Another nice feature of Microsoft’s methodology here is that they record and aggregate all of your deliverability reports – so there’s no need to have that email address monitored!

microsoft 365 security email spoofing reports

Appreciate this content?

Sign up for our weekly newsletter, which delivers our latest posts every Monday morning.

We don’t spam! Read our privacy policy for more info.

Douglas Karr

Douglas Karr is a fractional Chief Marketing Officer specializing in SaaS and AI companies, where he helps scale marketing operations, drive demand generation, and implement AI-powered strategies. He is the founder and publisher of Martech Zone, a leading publication in marketing technology, and a trusted advisor to startups and enterprises alike. With a track record spanning more than $5 billion in MarTech acquisitions and investments, Douglas has led go-to-market strategy, brand positioning, and digital transformation initiatives for companies ranging from early-stage startups to global tech leaders like Dell, GoDaddy, Salesforce, Oracle, and Adobe. A published author of Corporate Blogging for Dummies and contributor to The Better Business Book, Douglas is also a recognized speaker, curriculum developer, and Forbes contributor. A U.S. Navy veteran, he combines strategic leadership with hands-on execution to help organizations achieve measurable growth.

Related Articles

Back to top button
Close

Adblock Detected

We rely on ads and sponsorships to keep Martech Zone free. Please consider disabling your ad blocker—or support us with an affordable, ad-free annual membership ($10 US):

Sign Up For An Annual Membership