Fix guides › Microsoft 365 + Cloudflare

Set up SPF, DKIM and DMARC for Microsoft 365 with Cloudflare DNS

About 20 minutes, plus waiting time. You’ll add four kinds of record so inboxes trust your email and no one else can send email in your name.

Last reviewed 7 October 2026

Before you start, run the email health check on your domain so you can see what’s already in place. Menu names at Microsoft 365 and Cloudflare change from time to time; if a step looks different, look for the nearest equivalent.

1. Open your DNS records at Cloudflare

Sign in to the Cloudflare dashboard, select your domain, then go to DNS › Records. You’ll see your records and an Add record button.

Select Add record, choose the type, and fill in the Name and content. Cloudflare adds your domain to the name automatically, so type only the part shown below. Leave TTL on Auto.

2. Mail servers (MX)

In the Microsoft 365 admin centre, go to Settings › Domains, select your domain and open DNS records. Copy the MX value shown there (it ends in mail.protection.outlook.com or mx.microsoft) with priority 0. Add it as an MX record with Name @, and delete any old MX records from a previous provider.

3. Approved senders (SPF)

Add one TXT record:

TypeNameValue
TXT@v=spf1 include:spf.protection.outlook.com -all

If a TXT record starting with v=spf1 already exists (Cloudflare Email Routing adds one), select Edit and merge your entries into it instead of adding a second record. Your domain must have exactly one SPF record. If other services send email on your behalf (newsletters, invoicing, a help desk), add their include: to the same record. The SPF record builder does this for you and checks the 10-lookup limit.

4. Email signing (DKIM)

  1. Go to security.microsoft.com and open Email & collaboration › Policies & rules › Threat policies › Email authentication settings, then the DKIM tab.
  2. Select your domain. Microsoft shows two CNAME records, for selector1._domainkey and selector2._domainkey. Copy both values exactly as shown; they include your tenant name and can’t be guessed.
  3. Add both as CNAME records at Cloudflare. Set Proxy status to DNS only (grey cloud). Email records must never be proxied.
  4. Wait an hour or two, return to the DKIM tab and switch Sign messages for this domain with DKIM signatures to on. If Microsoft says it can’t find the records yet, wait a little longer and try again.

Our DKIM checker looks for selector1 and selector2 automatically. Run the DKIM checker to confirm the key is published.

5. Spoofing protection (DMARC)

Start in monitor-only mode so nothing breaks while you check that all your real email passes:

TypeNameValue
TXT_dmarcv=DMARC1; p=none; rua=mailto:dmarc-reports@yourdomain.com

Replace the address with a mailbox you control. After two to four weeks, once reports show your own email passing, move to p=quarantine and then p=reject. Our guide to moving DMARC from none to reject walks through it, and the DMARC record builder writes each step’s record.

6. Check your work

DNS changes usually appear within minutes but can take a few hours. Run the email health check again. You’re aiming for a pass on mail servers, SPF and DKIM, with DMARC showing “monitor only” for now.