How to Configure SPF, DKIM, and DMARC for Outlook.com Email
Question details
Configure SPF, DKIM, and DMARC records for a custom-domain Outlook.com email to improve authentication and delivery rates.

- Product
- Outlook.com
- Device & OS
- not provided
- Scenario
- Setting up email authentication for a custom domain linked to Outlook.com to prevent outgoing emails from bouncing or being marked as spam by strict providers like Gmail.
- Observed behavior
- Without these DNS records, custom domain emails sent via Outlook.com fail authentication checks and are often rejected or routed to the recipient's junk folder.
Ensure you have administrator access to both your Microsoft 365/Outlook admin portal and the DNS management dashboard of your domain registrar (e.g., GoDaddy, Namecheap, Cloudflare).
Add Authentication Records via Domain Registrar
Implement SPF, DKIM, and DMARC by adding specific TXT and CNAME records to your domain's DNS settings.
Email authentication relies on domain name system (DNS) records to prove to receiving servers that an email genuinely came from you. You must configure these records at your domain registrar, following Microsoft's specific parameter requirements.
Log into your domain registrar's DNS settings. Add a new TXT record for your domain (usually using '@' as the hostname). For Microsoft 365/Outlook, the standard value is typically 'v=spf1 include:spf.protection.outlook.com -all'. Save the record.
Go to the Microsoft 365 Defender portal under 'Email & collaboration' > 'Policies & rules' > 'Threat policies' > 'Email authentication settings' > 'DKIM'. Select your domain and create DKIM keys. Copy the generated CNAME records and add them to your domain registrar's DNS settings, then return to Microsoft to enable DKIM.
In your domain registrar's DNS settings, add a new TXT record with the hostname '_dmarc'. To start safely without blocking legitimate emails, use the value 'v=DMARC1; p=none;'. This 'p=none' policy will monitor your traffic and send reports without rejecting emails that fail checks.

Boost Your Productivity with WPS Office
While you are managing your domain and Outlook settings, consider upgrading your desktop document workflow. WPS Office is a powerful, lightweight, and free alternative to Microsoft Office that provides a highly compatible environment for your everyday tasks.
- 1. Download the Installer: Visit the official WPS Office website and click 'Download WPS Office Free' to get the installer for your operating system.
- 2. Install the Suite: Run the downloaded file and follow the simple on-screen instructions to install the software in seconds.
- 3. Open Your Office Files: Launch WPS Office and instantly open your existing Word, Excel, and PowerPoint files without worrying about formatting issues.

Frequently Asked Questions
Why are my Outlook emails going to Gmail spam?
Providers like Gmail enforce strict authentication policies. If your custom domain lacks properly configured SPF, DKIM, and DMARC records, Gmail cannot verify you as the legitimate sender and will likely route your emails to the spam folder or reject them entirely.
What does p=none mean in a DMARC record?
The 'p=none' tag is a monitoring policy. It tells receiving email servers to treat messages normally even if they fail authentication checks, while still sending reports back to you. This is highly recommended when first setting up DMARC so you can troubleshoot configuration issues before moving to stricter 'quarantine' or 'reject' policies.
How can I verify if my SPF and DKIM records are working?
You can use free online DNS lookup tools like MXToolbox or Google's Admin Toolbox to check your domain's TXT records. Additionally, sending a test email to a service like Mail-Tester can give you a detailed report on whether your SPF, DKIM, and DMARC signatures are passing.




