Quantcast
Channel: o365info
Viewing all articles
Browse latest Browse all 375

Add DKIM and DMARC for onmicrosoft.com domain in Microsoft 365

$
0
0

You should secure every domain in Microsoft 365 with the authentication methods SPF, DKIM, and DMARC. Microsoft automatically configures the SPF record for the onmicrosoft.com domain but not the DKIM and DMARC records. It’s essential to configure both the records for the onmicrosoft.com domain. In this article, you will learn how to add the DKIM and DMARC records for the onmicrosoft.com domain.

Microsoft Online Email Routing Address (MOERA)

The Microsoft Online Email Routing Address (MOERA) domain is the onmicrosoft.com domain in Microsoft 365. By default, every Microsoft tenant comes with an onmicrosoft.com domain.

You should always protect every domain with these authentication methods:

  • SPF record contains a list of authorized mail servers or IP addresses that are allowed to send emails on behalf of that domain. Microsoft configures, by default, the SPF record for the onmicrosoft.com (MOERA) domain. There is nothing that you have to add or change.
  • DKIM verifies that the sender and message content are both authentic. Microsoft doesn’t automatically add it, therefore, you need to add the DKIM record for the onmicrosoft.com domain in Microsoft 365.
  • DMARC improves email deliverability and security. Microsoft doesn’t automatically add the DMARC record, so you need to add the record for the onmicrosoft.com domain in Microsoft 365.

Important: You must always add a DKIM and DMARC TXT record for your onmicrosoft.com domain, whether you use it or not.

Add DKIM for onmicrosoft.com domain

DKIM stands for Domain Keys Identified Mail and is an email authentication protocol. DKIM consists of two selectors, so you need to add them both.

To add DKIM for your onmicrosoft.com domain, follow these steps:

  1. Sign in to Microsoft Defender
  2. Click Email & collaboration > Policies & rules
  3. Click Threat Policies
Microsoft Defender threat policies
  1. Click Email authentication settings
Email authentication settings for DKIM in Microsoft Defender
  1. Click the tab DKIM
  2. Click your onmicrosoft.com domain
  3. Select Enabled
Enable DKIM for onmicrosoft.com domain

Note: Wait about 15 minutes to an hour before the changes take effect.

It automatically adds the DKIM selector1 record for your onmicrosoft.com domain. You also need to add the DKIM selector2 record shown in the next step.

  1. Click Rotate DKIM keys to automatically add DKIM selector2 record to the DNS records

Note: It’s recommended that you Rotate DKIM keys in Microsoft 365 every 6 months for security purposes.

Add DMARC for onmicrosoft.com domain

You also need to add the DMARC record for your onmicrosoft.com domain.

To add the DMARC TXT record for your onmicrosoft.com domain, follow these steps:

  1. Sign in to Microsoft 365 admin center
  2. Click Settings > Domains
  3. Click onmicrosoft.com domain
  1. Click DNS records
  2. Click Add record
  3. Select TXT (Text)
  4. TXT name _dmarc
  5. TXT value v=DMARC1; p=reject
  6. TTL 1 hour
  7. Click Save

Note: The pct= value isn’t included because the default value is pct=100, which means all messages that fail DMARC get the DMARC policy applied to them. You don’t need the rua=mailto: and ruf=mailto: values because you don’t want to get any reports.

The DMARC record is now added to the onmicrosoft.com domain, which you can check in the next step.

Verify DKIM and DMARC enabled for onmicrosoft.com domain

To verify you added the DKIM and DMARC records for your onmicrosoft.com domain, follow these steps:

  1. Sign in to Microsoft 365 admin center
  2. Click Settings > Domains
  3. Click your onmicrosoft.com domain
Add DKIM and DMARC for onmicrosoft.com domain
  1. Click DNS records
  2. See the DMARC TXT record added under Custom records
Add DKIM and DMARC for onmicrosoft.com domain
  1. Under Additional Microsoft Office 365 records
  2. See the TXT record DKIM selector1 and selector2 for your onmicrosoft.com domain
Add DKIM and DMARC for onmicrosoft.com domain

That’s it!

Read more: How to find Microsoft 365 tenant domain name »

Conclusion

You learned how to add DKIM and DMARC records for the onmicrosoft.com domain in the Microsoft 365 admin center. Even if you don’t use the Microsoft Online Email Routing Address (MOERA) domain, you must always add both the DKIM and DMARC records for the domain. The SPF record is already configured, and you don’t have to do anything for that.

Did you enjoy this article? You may also like How to simulate spam mail. Don’t forget to follow us and share this article.


Viewing all articles
Browse latest Browse all 375

Trending Articles