Email Fix Pack

How to set up DMARC for Microsoft 365

Before you start

For custom domains, Microsoft says you must first configure SPF and DKIM signing with your own domain, so the signing domain aligns with the From address. There is no admin-portal tool for custom-domain DMARC: you create the TXT record at your domain registrar or DNS host. (For a *.onmicrosoft.com domain, use the DNS records tab in the Microsoft 365 admin center.)

Steps

  1. Start with monitoring only. Hostname _dmarc, TXT value:
    v=DMARC1; p=none; pct=100; rua=mailto:dmarc-reports@example.com
  2. Review aggregate reports and fix legitimate senders failing alignment.
  3. Raise the policy to quarantine, optionally stepping pct through 10, 25, 50, 75, 100:
    v=DMARC1; p=quarantine; pct=25; rua=mailto:dmarc-reports@example.com
  4. Move to reject once reports are clean:
    v=DMARC1; p=reject; pct=100; rua=mailto:dmarc-reports@example.com
  5. Do subdomains and parked domains too. Subdomains inherit the parent record unless they publish their own; parked domains that never send mail should use v=DMARC1; p=reject;.

Use one _dmarc TXT record per domain; duplicates cause errors.

Check your domain

Not sure what your domain publishes today? The checker reads your live DNS and shows what is missing. If you would rather skip the trial and error, the $29 Email Fix Pack is the fastest route: ready-to-paste records for your domain.

Check your domain free

Sources

  • Microsoft Learn: Set up DMARC to validate email in Microsoft 365

More email delivery fixes

Email Fix Pack

Terms · Privacy · Refunds