1. Find what is failing
- A message arrives badly: send it from your business address to a personal Gmail address, open it, and choose “Show original”. Gmail shows PASS or FAIL for SPF, DKIM, and DMARC.
- A message does not arrive: use message trace in the Exchange admin center to see what happened to the message, and the error code if it was rejected.
2. Fix DKIM
Microsoft 365 signs your email with DKIM using two CNAME records: selector1._domainkey and selector2._domainkey. Their values are specific to your domain and your tenant: Microsoft gives them to you in the Defender portal. The initial onmicrosoft.com domain is signed automatically; your custom domain is not until you turn it on.
- In the Microsoft Defender portal, open Email authentication settings, the DKIM tab, and select your domain.
- Copy the two values from the “Publish CNAMEs” section and create the two CNAME records at your DNS provider.
- Wait for Microsoft to detect them (a few minutes, sometimes longer), then turn DKIM on for the domain.
If the status shows CnameMissing, Microsoft cannot find your records. A frequent cause: the hostname typed with the domain doubled, or a typo in the copied value. If you rotate the keys later, the new key starts signing after four days (96 hours).
3. Two different protections against spoofing
- Protect your staff from spoofed email coming in: Exchange Online Protection validates SPF, DKIM, and DMARC on incoming messages, and the spoof intelligence check is on by default. Microsoft recommends leaving it on.
- Stop others from spoofing your domain: publish SPF, DKIM, and DMARC for your domain, then tighten DMARC to
quarantineandreject(see the SPF, DKIM, and DMARC guide).
4. Turn on the phishing protection in Business Premium
Microsoft 365 Business Premium includes Defender for Office 365 Plan 1. Its anti-phishing policies offer impersonation protection (users and domains) and mailbox intelligence. Microsoft says impersonation protection is not turned on in the default policy: you have to configure it. In the Defender portal, under threat policies, open Anti-phishing, then add key people (the owner, accounting) to user impersonation protection and your domains to domain impersonation protection. Microsoft also offers preset security policies (Standard and Strict).
The order I follow
- Read the headers of a failing message (PASS or FAIL).
- A single SPF record, then DKIM on for every service that sends in your name.
- DMARC at
p=nonewith reports, thenquarantine, thenreject. - Impersonation protection turned on in Defender.
- A test message to Gmail to confirm three PASS results.
I can fix it for you
I fix email delivery and set up SPF, DKIM, DMARC, and Defender protection for Montreal small businesses, remotely or on site. You get a written quote first, and I change nothing without your agreement.