Fix guides › Microsoft 365 + GoDaddy

Set up SPF, DKIM and DMARC for Microsoft 365 with GoDaddy DNS

About 20 minutes, plus waiting time. You’ll add four kinds of record so inboxes trust your email and no one else can send email in your name.

Last reviewed 7 October 2026

Before you start, run the email health check on your domain so you can see what’s already in place. Menu names at Microsoft 365 and GoDaddy change from time to time; if a step looks different, look for the nearest equivalent.

1. Open your DNS records at GoDaddy

Sign in to GoDaddy, open My Products (or Domain Portfolio), select your domain and choose DNS. You’ll see a list of your records and an Add New Record button.

Select Add New Record, choose the type, and fill in the Name and Value. GoDaddy adds your domain to the name automatically, so type only the part shown below. Leave TTL at the default (1 hour).

2. Mail servers (MX)

In the Microsoft 365 admin centre, go to Settings › Domains, select your domain and open DNS records. Copy the MX value shown there (it ends in mail.protection.outlook.com or mx.microsoft) with priority 0. Add it as an MX record with Name @, and delete any old MX records from a previous provider.

3. Approved senders (SPF)

Add one TXT record:

TypeNameValue
TXT@v=spf1 include:spf.protection.outlook.com -all

If a TXT record starting with v=spf1 already exists, select the pencil icon to edit it instead of adding a new one. Your domain must have exactly one SPF record. If other services send email on your behalf (newsletters, invoicing, a help desk), add their include: to the same record. The SPF record builder does this for you and checks the 10-lookup limit.

4. Email signing (DKIM)

  1. Go to security.microsoft.com and open Email & collaboration › Policies & rules › Threat policies › Email authentication settings, then the DKIM tab.
  2. Select your domain. Microsoft shows two CNAME records, for selector1._domainkey and selector2._domainkey. Copy both values exactly as shown; they include your tenant name and can’t be guessed.
  3. Add both as CNAME records at GoDaddy.
  4. Wait an hour or two, return to the DKIM tab and switch Sign messages for this domain with DKIM signatures to on. If Microsoft says it can’t find the records yet, wait a little longer and try again.

Our DKIM checker looks for selector1 and selector2 automatically. Run the DKIM checker to confirm the key is published.

5. Spoofing protection (DMARC)

Start in monitor-only mode so nothing breaks while you check that all your real email passes:

TypeNameValue
TXT_dmarcv=DMARC1; p=none; rua=mailto:dmarc-reports@yourdomain.com

Replace the address with a mailbox you control. After two to four weeks, once reports show your own email passing, move to p=quarantine and then p=reject. Our guide to moving DMARC from none to reject walks through it, and the DMARC record builder writes each step’s record.

6. Check your work

DNS changes usually appear within minutes but can take a few hours. Run the email health check again. You’re aiming for a pass on mail servers, SPF and DKIM, with DMARC showing “monitor only” for now.