To set up SPF for Microsoft 365, you add one TXT record to your domain's DNS that includes Microsoft's servers: v=spf1 include:spf.protection.outlook.com ~all. If your domain already has an SPF record, add the include to that record instead of creating a second one, because two SPF records make SPF fail for every email you send.
SPF (Sender Policy Framework) is a list of the servers allowed to send email for your domain. If Microsoft 365 isn't on it, your email fails SPF and is more likely to land in junk.
Before you start
You need access to your DNS. DNS is the set of records that tells the internet where your website and email live. It's usually managed where you bought your domain, such as GoDaddy, Crazy Domains or VentraIP, or by your web host.
There's no SPF setting inside Microsoft 365. You create the record at your DNS host. If you only send from your original yourbusiness.onmicrosoft.com address, you don't need to do anything: Microsoft looks after SPF for that domain.
Step 1: Check what you have now
Sign in to your DNS host and open the records for yourbusiness.com.au. Look at the TXT records on the main domain (often shown as @ or a blank name) for one that starts with v=spf1.
- No SPF record? Go to Step 2.
- One SPF record? Go to Step 3.
- Two or more? Go to Step 3. You'll merge them into one.
To see the record Microsoft expects, open the Microsoft 365 admin center, go to Settings → Domains (under Show all), choose your domain and select DNS records. If the screen has moved, look for your domain's DNS records.
Step 2: Add a new SPF record
If you have no SPF record, add this one:
| Type | Name | Value |
|---|---|---|
| TXT | yourbusiness.com.au | v=spf1 include:spf.protection.outlook.com ~all |
Most DNS hosts want @ or a blank name for the main domain; some want the full domain name. If asked for a TTL, Microsoft suggests 3600 seconds (one hour).
The Microsoft 365 admin center shows the same record ending in -all. Both work; see "~all or -all" below.
Step 3: Add Microsoft 365 to your existing record
Don't create a second record. Edit yours and add include:spf.protection.outlook.com just before the ~all or -all at the end. Our report gives you the finished record when Microsoft 365 is missing.
| Before | After |
|---|---|
v=spf1 ip4:203.0.113.10 ~all | v=spf1 ip4:203.0.113.10 include:spf.protection.outlook.com ~all |
If you have two SPF records
This often happens when a newsletter or booking tool asks for SPF and someone adds a second record. Receivers can't tell which one to use, so SPF fails for all your email, including Microsoft 365's.
Merge them into a single TXT record that starts with v=spf1 and delete the others:
- Record 1:
v=spf1 include:spf.protection.outlook.com ~all - Record 2:
v=spf1 include:<your newsletter service> ~all - Merged:
v=spf1 include:spf.protection.outlook.com include:<your newsletter service> ~all
One v=spf1 at the start, one all at the end, and each include only once.
What about Xero, MYOB and your website?
SPF must list every service that sends email with your address in the From line. But many services that send for you don't use your address.
| Service | Add it to SPF? |
|---|---|
| Xero invoices | No. Xero sends from its own address (messaging-service@post.xero.com) and looks after its own SPF and DKIM. |
| MYOB invoices | No, when MYOB sends them from its @apps.myob.com address. If you send them through Outlook, the Microsoft include covers them. |
| Website contact forms | Only if they send as you. It's better to send them through Microsoft 365 or an email service. Never add a shared web server's address. |
| Newsletter, CRM or booking tools | Yes, if they send as you. Use the include: value from the service's help pages, and set up DKIM there too. |
Microsoft also suggests sending newsletters from a subdomain, such as news.yourbusiness.com.au, so problems there don't affect your everyday email. A subdomain needs its own SPF record.
The 10-lookup limit and common typos
Receivers will only do 10 DNS lookups while checking your record. Each include:, a, mx, exists and redirect uses at least one, and includes inside includes count too. Over 10, your record is treated as broken. Microsoft's include uses one.
To get back under 10, remove include: entries for services you no longer use, including an old email provider's, or ask your provider for a smaller ("flattened") include. Microsoft says not to flatten its own include, because its addresses change often.
Microsoft also lists the typos that break SPF most often: a full stop after the domain (outlook.com.), an equals sign instead of a colon (include=), and a space after the colon.
~all or -all?
The ending tells receivers what to do with email from servers that aren't listed. ~all (soft fail) asks them to treat it as suspicious, and -all (hard fail) says it isn't allowed. Never use +all.
Our reports suggest ~all when you first set up SPF. Microsoft recommends -all for Microsoft 365 domains once DKIM and DMARC are set up. Its reasoning: DMARC treats both as an SPF failure, but with ~all a receiver may not act on a failing email that also has no DKIM signature.
So start with ~all, set up DKIM and DMARC, and switch to -all once your DMARC reports show every genuine sender passing.
Check it worked
DNS changes often show up within an hour, but can take up to 48 hours. Then send an email from your Microsoft 365 mailbox to your free test address.
The report shows whether SPF passed for yourbusiness.com.au itself, which is what DMARC needs. It also flags a second SPF record or too many lookups, and gives you the exact record to publish if anything needs fixing. Test each other service that sends as you the same way.
SPF is one of three checks. Next, set up DKIM and then DMARC, so email from Microsoft 365 passes all three.
Checked against: Microsoft Learn, Set up SPF to identify valid email sources for your Microsoft 365 domain · Microsoft Learn, Connect your domain by adding DNS records · Microsoft Learn, Troubleshoot email authentication in Microsoft 365 · RFC 7208, Sender Policy Framework (SPF).