How do I set up SPF for Microsoft 365?

Updated 9 October 2026 · 5 min read

Guest list

To set up SPF for Microsoft 365, you add one TXT record to your domain's DNS that includes Microsoft's servers: v=spf1 include:spf.protection.outlook.com ~all. If your domain already has an SPF record, add the include to that record instead of creating a second one, because two SPF records make SPF fail for every email you send.

SPF (Sender Policy Framework) is a list of the servers allowed to send email for your domain. If Microsoft 365 isn't on it, your email fails SPF and is more likely to land in junk.

Before you start

You need access to your DNS. DNS is the set of records that tells the internet where your website and email live. It's usually managed where you bought your domain, such as GoDaddy, Crazy Domains or VentraIP, or by your web host.

There's no SPF setting inside Microsoft 365. You create the record at your DNS host. If you only send from your original yourbusiness.onmicrosoft.com address, you don't need to do anything: Microsoft looks after SPF for that domain.

Step 1: Check what you have now

Sign in to your DNS host and open the records for yourbusiness.com.au. Look at the TXT records on the main domain (often shown as @ or a blank name) for one that starts with v=spf1.

  • No SPF record? Go to Step 2.
  • One SPF record? Go to Step 3.
  • Two or more? Go to Step 3. You'll merge them into one.

To see the record Microsoft expects, open the Microsoft 365 admin center, go to Settings → Domains (under Show all), choose your domain and select DNS records. If the screen has moved, look for your domain's DNS records.

Step 2: Add a new SPF record

If you have no SPF record, add this one:

TypeNameValue
TXTyourbusiness.com.auv=spf1 include:spf.protection.outlook.com ~all

Most DNS hosts want @ or a blank name for the main domain; some want the full domain name. If asked for a TTL, Microsoft suggests 3600 seconds (one hour).

The Microsoft 365 admin center shows the same record ending in -all. Both work; see "~all or -all" below.

Step 3: Add Microsoft 365 to your existing record

Don't create a second record. Edit yours and add include:spf.protection.outlook.com just before the ~all or -all at the end. Our report gives you the finished record when Microsoft 365 is missing.

BeforeAfter
v=spf1 ip4:203.0.113.10 ~allv=spf1 ip4:203.0.113.10 include:spf.protection.outlook.com ~all

If you have two SPF records

This often happens when a newsletter or booking tool asks for SPF and someone adds a second record. Receivers can't tell which one to use, so SPF fails for all your email, including Microsoft 365's.

Merge them into a single TXT record that starts with v=spf1 and delete the others:

  • Record 1: v=spf1 include:spf.protection.outlook.com ~all
  • Record 2: v=spf1 include:<your newsletter service> ~all
  • Merged: v=spf1 include:spf.protection.outlook.com include:<your newsletter service> ~all

One v=spf1 at the start, one all at the end, and each include only once.

What about Xero, MYOB and your website?

SPF must list every service that sends email with your address in the From line. But many services that send for you don't use your address.

ServiceAdd it to SPF?
Xero invoicesNo. Xero sends from its own address (messaging-service@post.xero.com) and looks after its own SPF and DKIM.
MYOB invoicesNo, when MYOB sends them from its @apps.myob.com address. If you send them through Outlook, the Microsoft include covers them.
Website contact formsOnly if they send as you. It's better to send them through Microsoft 365 or an email service. Never add a shared web server's address.
Newsletter, CRM or booking toolsYes, if they send as you. Use the include: value from the service's help pages, and set up DKIM there too.

Microsoft also suggests sending newsletters from a subdomain, such as news.yourbusiness.com.au, so problems there don't affect your everyday email. A subdomain needs its own SPF record.

The 10-lookup limit and common typos

Receivers will only do 10 DNS lookups while checking your record. Each include:, a, mx, exists and redirect uses at least one, and includes inside includes count too. Over 10, your record is treated as broken. Microsoft's include uses one.

To get back under 10, remove include: entries for services you no longer use, including an old email provider's, or ask your provider for a smaller ("flattened") include. Microsoft says not to flatten its own include, because its addresses change often.

Microsoft also lists the typos that break SPF most often: a full stop after the domain (outlook.com.), an equals sign instead of a colon (include=), and a space after the colon.

~all or -all?

The ending tells receivers what to do with email from servers that aren't listed. ~all (soft fail) asks them to treat it as suspicious, and -all (hard fail) says it isn't allowed. Never use +all.

Our reports suggest ~all when you first set up SPF. Microsoft recommends -all for Microsoft 365 domains once DKIM and DMARC are set up. Its reasoning: DMARC treats both as an SPF failure, but with ~all a receiver may not act on a failing email that also has no DKIM signature.

So start with ~all, set up DKIM and DMARC, and switch to -all once your DMARC reports show every genuine sender passing.

Check it worked

DNS changes often show up within an hour, but can take up to 48 hours. Then send an email from your Microsoft 365 mailbox to your free test address.

The report shows whether SPF passed for yourbusiness.com.au itself, which is what DMARC needs. It also flags a second SPF record or too many lookups, and gives you the exact record to publish if anything needs fixing. Test each other service that sends as you the same way.

SPF is one of three checks. Next, set up DKIM and then DMARC, so email from Microsoft 365 passes all three.

Checked against: Microsoft Learn, Set up SPF to identify valid email sources for your Microsoft 365 domain · Microsoft Learn, Connect your domain by adding DNS records · Microsoft Learn, Troubleshoot email authentication in Microsoft 365 · RFC 7208, Sender Policy Framework (SPF).

Questions people ask

Does Microsoft 365 add the SPF record for me?

Only if your DNS host supports Domain Connect and you let the Microsoft 365 setup wizard add the records. Otherwise you add it yourself at your DNS host. Either way, check it's there and that it's the only SPF record on your domain.

Do I need to add Xero or MYOB to my SPF record?

No. Xero and MYOB send invoices from their own addresses, so receivers check their SPF records, not yours. If you send MYOB invoices through Outlook, they go out through Microsoft 365, which your Microsoft include already covers.

I have two SPF records. Which one should I delete?

Neither, as they stand. Copy every include and ip4 entry into one record that starts with v=spf1 and ends with a single ~all, then delete the other. Two records make SPF fail for all your email.

Do I need SPF for my onmicrosoft.com address?

No. Microsoft owns onmicrosoft.com and looks after its SPF record for you. You only set up SPF for your own domains, such as yourbusiness.com.au.