Fix guides › Microsoft 365 + Cloudflare
Set up SPF, DKIM and DMARC for Microsoft 365 with Cloudflare DNS
About 20 minutes, plus waiting time. You’ll add four kinds of record so inboxes trust your email and no one else can send email in your name.
Last reviewed 7 October 2026
Before you start, run the email health check on your domain so you can see what’s already in place. Menu names at Microsoft 365 and Cloudflare change from time to time; if a step looks different, look for the nearest equivalent.
1. Open your DNS records at Cloudflare
Sign in to the Cloudflare dashboard, select your domain, then go to DNS › Records. You’ll see your records and an Add record button.
Select Add record, choose the type, and fill in the Name and content. Cloudflare adds your domain to the name automatically, so type only the part shown below. Leave TTL on Auto.
2. Mail servers (MX)
In the Microsoft 365 admin centre, go to Settings › Domains, select your domain and open DNS records. Copy the MX value shown there (it ends in mail.protection.outlook.com or mx.microsoft) with priority 0. Add it as an MX record with Name @, and delete any old MX records from a previous provider.
3. Approved senders (SPF)
Add one TXT record:
| Type | Name | Value |
|---|---|---|
| TXT | @ | v=spf1 include:spf.protection.outlook.com -all |
If a TXT record starting with v=spf1 already exists (Cloudflare Email Routing adds one), select Edit and merge your entries into it instead of adding a second record. Your domain must have exactly one SPF record. If other services send email on your behalf (newsletters, invoicing, a help desk), add their include: to the same record. The SPF record builder does this for you and checks the 10-lookup limit.
4. Email signing (DKIM)
- Go to security.microsoft.com and open Email & collaboration › Policies & rules › Threat policies › Email authentication settings, then the DKIM tab.
- Select your domain. Microsoft shows two CNAME records, for
selector1._domainkeyandselector2._domainkey. Copy both values exactly as shown; they include your tenant name and can’t be guessed. - Add both as CNAME records at Cloudflare. Set Proxy status to DNS only (grey cloud). Email records must never be proxied.
- Wait an hour or two, return to the DKIM tab and switch Sign messages for this domain with DKIM signatures to on. If Microsoft says it can’t find the records yet, wait a little longer and try again.
Our DKIM checker looks for selector1 and selector2 automatically. Run the DKIM checker to confirm the key is published.
5. Spoofing protection (DMARC)
Start in monitor-only mode so nothing breaks while you check that all your real email passes:
| Type | Name | Value |
|---|---|---|
| TXT | _dmarc | v=DMARC1; p=none; rua=mailto:dmarc-reports@yourdomain.com |
Replace the address with a mailbox you control. After two to four weeks, once reports show your own email passing, move to p=quarantine and then p=reject. Our guide to moving DMARC from none to reject walks through it, and the DMARC record builder writes each step’s record.
6. Check your work
DNS changes usually appear within minutes but can take a few hours. Run the email health check again. You’re aiming for a pass on mail servers, SPF and DKIM, with DMARC showing “monitor only” for now.