logo
search
Send & Receive Issues

Fix Exchange Emails Rejected Due to Missing SPF, DKIM, and DMARC

Tauseeq MagsiTauseeq Magsi Oct 9, 2026 868 views

Question details

Outbound Exchange emails are being rejected by recipient servers due to missing email authentication records.

Fix Exchange Emails Rejected Due to Missing SPF, DKIM, and DMARC
Product
Microsoft Exchange
Device & OS
not provided
Scenario
Sending emails to external providers like Bigpond from an Exchange environment or Microsoft hosted infrastructure.
Observed behavior
Messages are rejected and bounce back, with email headers indicating that mail is unauthenticated (spf=none, dkim=none, and dmarc=none).
Before you start

Ensure you have administrator access to your domain's DNS management portal and your Exchange Admin Center before making changes to mail flow settings.

Solution 1Recommended

Configure SPF, DKIM, and DMARC DNS Records

Publishing these authentication records verifies your sending domain, ensuring strict external email providers do not mark your messages as spam.

Major email providers enforce strict authentication policies. If your Exchange environment is not signing outbound emails or lacks a published sender policy, recipients will automatically reject the connections.

1
Access DNS Management

Log into the control panel of your domain registrar (e.g., GoDaddy, Cloudflare) and navigate to the DNS settings or Zone Editor for your sending domain.

2
Add an SPF Record

Click 'Add Record', select 'TXT' as the type, and enter your SPF string in the value field (for Microsoft 365, this is typically 'v=spf1 include:spf.protection.outlook.com -all'). Save the record.

3
Enable DKIM Signing

Open the Exchange Admin Center, navigate to 'Protection' then 'DKIM'. Select your domain, click 'Enable', and publish the two provided CNAME records to your DNS provider.

4
Publish a DMARC Policy

Create another TXT record in your DNS named '_dmarc'. Set the value to 'v=DMARC1; p=quarantine;' to instruct receiving servers how to handle messages that fail SPF or DKIM checks.

Configure SPF, DKIM, and DMARC DNS Records
DNS Propagation Time: DNS changes can take up to 48 hours to fully propagate worldwide. You may need to wait before testing email delivery to the rejecting address again.
Free Microsoft Office alternative

Looking for a Lightweight Alternative to Microsoft Office?

While resolving complex Exchange server DNS issues, your actual document workflow shouldn't be a hassle. WPS Office offers a completely free, fast, and highly compatible alternative to Microsoft Office, letting you handle documents, spreadsheets, and presentations without the heavy overhead.

Fully compatible with Microsoft Word, Excel, and PowerPoint formats (.docx, .xlsx, .pptx).Includes a built-in PDF toolkit for seamless editing, merging, and conversion.Lightweight application that runs smoothly even on older hardware with no complex setups.Familiar user interface requiring zero learning curve for users switching from Microsoft Office.
microsoft office alternative - wps office

Frequently Asked Questions

Why are providers like Bigpond rejecting my Exchange emails?

Internet Service Providers and email hosts enforce strict security policies to combat spam and phishing. If your domain is missing SPF, DKIM, and DMARC records, the receiving server cannot verify that the email actually originated from you, causing it to reject the connection.

How do I check if my emails have SPF and DKIM set up correctly?

You can inspect the email headers of a delivered message by opening the message properties in the recipient's inbox and looking for 'Authentication-Results'. Alternatively, use online DNS check tools like MXToolbox to scan your domain's published records.

Can I fix the spf=none error directly in Microsoft Outlook?

No, SPF, DKIM, and DMARC are domain-level DNS configurations. You cannot fix them within the Outlook desktop client. You must update the DNS records via your domain registrar and ensure your Exchange server is properly configured to sign outbound mail.