How do I set up DMARC for Microsoft 365?

For your own domain, Microsoft 365 has no DMARC switch: you add a TXT record named _dmarc wherever your domain's DNS lives. Set up SPF, turn on DKIM signing for your domain in the Defender portal, then add DMARC with p=none. Once your real email arrives normally, change it to p=quarantine and keep a dated check result.
DMARC is a record on your email domain that tells other mail servers what to do with fake email pretending to be from you. It works with SPF and DKIM, so you set up all three.
Check if you already have it
Run the free email check on HowyGuard with your business domain. It shows whether SPF, DKIM and DMARC are each set up. If all three pass and DMARC says p=quarantine or p=reject, you're done.
How to set it up
You need a Microsoft 365 admin sign-in and a sign-in for wherever your domain's DNS lives, usually the company you bought the domain from. Microsoft has no page in Microsoft 365 for DMARC on your own domain, so that record always goes in your DNS settings.
Also list anything else that sends email as you, like booking reminders, newsletters or your website's contact form. Search each one's help pages for "SPF" and "DKIM" and add what they give you, or their mail may go to junk later.
Set up SPF, DKIM and DMARC for Microsoft 365
Microsoft 365, needs a Microsoft 365 admin sign-in and your domain's DNS settings
- Sign in where your domain's DNS settings live. That's usually where you bought the domain, like GoDaddy, Namecheap, Squarespace or Wix. Look for DNS or Manage DNS.
- SPF: add a TXT record with the name
@and this value. Keep one SPF record only.v=spf1 include:spf.protection.outlook.com ~all - DKIM: sign in at
security.microsoft.com, go to Email & collaboration, then Policies & rules, then Threat policies, then Email authentication settings, and open the DKIM tab. Select your domain and add the two CNAME records Microsoft shows to your DNS. Then switch on Sign messages for this domain with DKIM signatures. - DMARC: add a TXT record with the name
_dmarcand this value, using an inbox you read:v=DMARC1; p=none; rua=mailto:you@yourbusiness.ca - Leave it on
p=noneat first. Once the DMARC reports show your real email arriving normally, changep=nonetop=quarantine.
How to show it's true: Run the free email check on howyguard.com and screenshot the result showing all three passing.
- You already have an SPF record: edit it instead of adding a second one.
If your only email addresses end in onmicrosoft.com, there's no domain of your own to set up. Microsoft says to add DMARC for that domain in the Microsoft 365 admin center, under Domains.
How to show it's done
Run the free email check again and keep a dated screenshot showing all three passing. Note the date you changed to p=quarantine. File both in your proof folder.
Common questions
What do p=none and p=quarantine mean?
p=none means "report only, deliver everything". p=quarantine sends email that fails the checks to junk. p=reject refuses it outright. Microsoft recommends getting there step by step.
I already have an SPF record from my website company. Do I add another?
No. Edit the one you have and add Microsoft's include to it.
I can't open the DKIM page in step 3. What now?
Your account may not have the right admin role. Ask whoever manages your Microsoft 365, or a tech.
Sources
- Microsoft Learn: Set up DMARC to validate the From address domainlearn.microsoft.com
- Microsoft Learn: Set up SPF to identify valid email sourceslearn.microsoft.com
- Microsoft Learn: Set up DKIM to sign mail from your domainlearn.microsoft.com