Microsoft 365 Email Security
Make sure attackers can’t spoof your Microsoft 365 domain. Check your SPF and DMARC records in seconds with our free tool, then assess email authentication as part of your whole tenant’s health.
The DMARC checker needs only a domain name — no signup, no tenant access.
Microsoft 365 email security starts with email authentication — the SPF, DKIM and DMARC records that let receiving servers tell your real mail from a spoof. M365 Health Score checks your domain’s SPF and DMARC by direct DNS lookup and flags what’s missing.
SPF, DKIM and DMARC — plainly
| Record | What it does | In Microsoft 365 |
|---|---|---|
| SPF | Lists which servers are allowed to send mail for your domain. | Must include Microsoft 365’s send hosts. Checked by DNS lookup. |
| DKIM | Adds a cryptographic signature receivers can verify. | Uses selector1/selector2 by default. We report a positive, never a false “missing”. |
| DMARC | Tells receivers what to do with mail that fails SPF/DKIM, and where to send reports. | Without a DMARC policy, spoofed mail isn’t rejected. Checked definitively. |
Why this belongs in a tenant health check
Exchange Online is one of the most spoofed mail platforms in the world, and business email compromise routinely relies on domains with no DMARC policy. Email authentication is one of five pillars in the full Microsoft 365 health check — checked alongside identity, Secure Score, app consent and license efficiency — so a spoofable domain doesn’t slip past a security review.
You don’t need to connect your tenant to check email authentication. Run the free DMARC checker on your domain first, then assess the rest of the tenant when you’re ready.
Microsoft 365 email security FAQ
What is Microsoft 365 email authentication?
Email authentication is how receiving servers verify that mail claiming to be from your domain is genuine. It rests on three DNS records — SPF (which servers may send for you), DKIM (a cryptographic signature), and DMARC (what to do with mail that fails). Together they stop attackers spoofing your domain.
How do I check DMARC for Microsoft 365?
Look up the TXT record at _dmarc.yourdomain.com. If it’s missing, mail that fails authentication isn’t being rejected or quarantined. Our free DMARC checker does this lookup for you and explains what to fix.
Does M365 Health Score check DKIM?
It checks for DKIM at Microsoft 365’s common selectors and reports it when found, but it never reports a hard “DKIM missing” — a custom selector wouldn’t be detected, so a negative wouldn’t be reliable. SPF and DMARC are checked definitively.
Why does email authentication matter for Microsoft 365?
Exchange Online is a prime target for domain spoofing and business email compromise. Without a DMARC policy, spoofed invoices and phishing that appear to come from your own domain can reach recipients unchallenged.
Check your email security, then your whole tenant
Verify SPF and DMARC on your domain now — then run a free, read-only assessment of your entire Microsoft 365 tenant.