Fix Exchange Emails Rejected Due to Missing SPF, DKIM, and DMARC
Question details
Outbound Exchange emails are being rejected by recipient servers due to missing email authentication records.

- Product
- Microsoft Exchange
- Device & OS
- not provided
- Scenario
- Sending emails to external providers like Bigpond from an Exchange environment or Microsoft hosted infrastructure.
- Observed behavior
- Messages are rejected and bounce back, with email headers indicating that mail is unauthenticated (spf=none, dkim=none, and dmarc=none).
Ensure you have administrator access to your domain's DNS management portal and your Exchange Admin Center before making changes to mail flow settings.
Configure SPF, DKIM, and DMARC DNS Records
Publishing these authentication records verifies your sending domain, ensuring strict external email providers do not mark your messages as spam.
Major email providers enforce strict authentication policies. If your Exchange environment is not signing outbound emails or lacks a published sender policy, recipients will automatically reject the connections.
Log into the control panel of your domain registrar (e.g., GoDaddy, Cloudflare) and navigate to the DNS settings or Zone Editor for your sending domain.
Click 'Add Record', select 'TXT' as the type, and enter your SPF string in the value field (for Microsoft 365, this is typically 'v=spf1 include:spf.protection.outlook.com -all'). Save the record.
Open the Exchange Admin Center, navigate to 'Protection' then 'DKIM'. Select your domain, click 'Enable', and publish the two provided CNAME records to your DNS provider.
Create another TXT record in your DNS named '_dmarc'. Set the value to 'v=DMARC1; p=quarantine;' to instruct receiving servers how to handle messages that fail SPF or DKIM checks.

Contact Microsoft Support for Hosted Infrastructure
Use this solution if your message headers indicate emails are sent through Microsoft-hosted servers that you cannot manually configure.
Looking for a Lightweight Alternative to Microsoft Office?
While resolving complex Exchange server DNS issues, your actual document workflow shouldn't be a hassle. WPS Office offers a completely free, fast, and highly compatible alternative to Microsoft Office, letting you handle documents, spreadsheets, and presentations without the heavy overhead.

Frequently Asked Questions
Why are providers like Bigpond rejecting my Exchange emails?
Internet Service Providers and email hosts enforce strict security policies to combat spam and phishing. If your domain is missing SPF, DKIM, and DMARC records, the receiving server cannot verify that the email actually originated from you, causing it to reject the connection.
How do I check if my emails have SPF and DKIM set up correctly?
You can inspect the email headers of a delivered message by opening the message properties in the recipient's inbox and looking for 'Authentication-Results'. Alternatively, use online DNS check tools like MXToolbox to scan your domain's published records.
Can I fix the spf=none error directly in Microsoft Outlook?
No, SPF, DKIM, and DMARC are domain-level DNS configurations. You cannot fix them within the Outlook desktop client. You must update the DNS records via your domain registrar and ensure your Exchange server is properly configured to sign outbound mail.




