SPF • DKIM • DMARC Setup for Microsoft 365 — Stop Phishing Dead
Authorizes allowed mail servers (like Microsoft's) to send emails on your behalf.
Location: TXT record in YOUR DNS
Signs emails with a cryptographic key — proves the email hasn't been tampered with.
Location: CNAME records in DNS + Enable in Defender
Policy engine that says: "If SPF or DKIM fail → quarantine or reject the email"
Location: TXT record in YOUR DNS
🔑 ONE PLACE FOR RECORDS: Your DNS Provider
Microsoft gives you the values and enables DKIM signing — but the internet checks YOUR DNS to trust the emails.
Add domain, get record values, start the setup wizard
SPF TXT • DKIM CNAME • DMARC TXT
Enable DKIM signing toggle