Microsoft weights sender reputation via SNDS and JMRP, and rejects unauthenticated bulk mail to consumer Outlook.com addresses.
What DMARC policies are#
DMARC (Domain-based Message Authentication, Reporting and Conformance) tells receivers what to do when a message fails SPF and DKIM alignment, and asks them to send aggregate and forensic reports back to the domain owner.
Why it matters#
DMARC at p=reject is what actually stops exact-domain spoofing. Gmail and Yahoo require at least p=none for bulk senders, and BIMI requires p=quarantine or p=reject.
Setting up DMARC policies for Outlook and Microsoft 365#
- Confirm SPF and DKIM are deployed and aligned for every legitimate sender.
- Publish _dmarc.yourdomain.com with v=DMARC1; p=none; rua=mailto:dmarc@yourdomain.com to begin collecting reports.
- Analyze aggregate (RUA) reports for 2 to 4 weeks to identify unauthenticated legitimate sources.
- Fix each source, then move to p=quarantine with pct=25, ramping to 100.
- Move to p=reject and add sp=reject to cover subdomains.
_dmarc.example.com. IN TXT "v=DMARC1; p=reject; sp=reject; rua=mailto:dmarc-rua@example.com; adkim=s; aspf=s; pct=100"How Outlook and Microsoft 365 reports results#
Open a delivered test message in Outlook and Microsoft 365 and view the original or headers. Look for Authentication-Results and any provider-specific verdict headers. Use the provider's sender dashboard for aggregate reputation.
Common mistakes#
- Jumping straight to p=reject and blocking your own invoicing or HR system.
- Sending RUA reports to a mailbox nobody reads; use a report processor.
- Leaving subdomains uncovered because sp= was never set.
- Assuming p=none provides protection; it is monitoring only.
Frequently asked questions#
What is DMARC alignment?
The domain in the visible From header must match (exactly or organizationally) the domain that passed SPF or DKIM. Set adkim=s and aspf=s for strict matching.
How long until I can reach p=reject?
Typically 4 to 12 weeks depending on how many third-party senders you have to fix.
What are RUA and RUF reports?
RUA are daily aggregate XML reports of pass/fail counts per source. RUF are per-message forensic samples; many receivers no longer send them.
Does Outlook and Microsoft 365 require DMARC policies?
Microsoft weights sender reputation via SNDS and JMRP, and rejects unauthenticated bulk mail to consumer Outlook.com addresses. Treat DMARC policies as required for any meaningful volume.