Provider repair guideReviewed 2026-08-07By HostWithShery technical editorial

Add or fix Microsoft 365 SPF

Maintain one SPF TXT record and include spf.protection.outlook.com together with any other legitimate senders.

Start with evidence from your own domain before changing DNS, SSL or mail settings.
Check your own configuration

Email Health Check

This page is preconfigured with the Email Health Check that best matches this problem.

No accountPublic evidence only
Live public check

Checks MX routing plus SPF, DKIM discovery, DMARC, BIMI, MTA-STS and TLS-RPT public signals.

No account · Public configuration only
On this page

Add or fix Microsoft 365 SPF: when this repair path applies

Maintain one SPF TXT record and include spf.protection.outlook.com together with any other legitimate senders. Use these steps when SPF is missing, duplicated or does not authorize Exchange Online, but first run the embedded diagnostic so the business-email DNS and mail authentication evidence supports this provider-specific path rather than a neighboring DNS, TLS, application or mail cause.

Find the authoritative setting before editing

Microsoft 365 Admin Center for assigned DNS values and the authoritative DNS provider for publication. For Add or fix Microsoft 365 SPF, confirm the active nameservers and exact service owner before changing find every v=spf1 TXT. A DNS-looking screen at microsoft-365 has no public effect when another provider is authoritative for the zone.

Evidence to save for Add or fix Microsoft 365 SPF

Record the current public state for find every v=spf1 TXT, merge into one record, check DNS lookup count. This gives the repair a before/after comparison and prevents a cached answer or a separate working service from being confused with the configuration that produced the symptom.

  • Find every v=spf1 TXTInspect the single public v=spf1 policy, validate its terms and count DNS-query-causing mechanisms; duplicate policies or excessive lookups can invalidate SPF.
  • Merge into one recordVerify merge into one record from the public Internet and compare it with the value the responsible provider says should be live.
  • Check DNS lookup countVerify check DNS lookup count from the public Internet and compare it with the value the responsible provider says should be live.
  • Validate after publishVerify validate after publish from the public Internet and compare it with the value the responsible provider says should be live.

Repair steps in microsoft-365

Maintain one SPF TXT record and include spf.protection.outlook.com together with any other legitimate senders.

  • 1. Find every v=spf1 TXT. After this step, check the public value tied to find every v=spf1 txt before changing another unrelated setting.
  • 2. Merge into one record. After this step, check the public value tied to merge into one record before changing another unrelated setting.
  • 3. Check DNS lookup count. After this step, check the public value tied to check dns lookup count before changing another unrelated setting.
  • 4. Validate after publish. After this step, check the public value tied to validate after publish before changing another unrelated setting.

Why this order matters for microsoft-365

The sequence begins with the provider/authority decision, then moves through find every v=spf1 TXT, merge into one record, check DNS lookup count. That keeps the change scoped to the failed business-email DNS and mail authentication path and avoids replacing nameservers, mail authentication or another healthy service just to make a provider dashboard indicator change.

Verify Add or fix Microsoft 365 SPF

The public MX/authentication records should match the intended mail provider, required hostnames should resolve, and the relevant SPF/DKIM/DMARC check should no longer show the original failure. Compare the same find every v=spf1 TXT and merge into one record evidence used before the change; a repair is complete when the public result agrees, not merely when the microsoft-365 interface reports that a save succeeded.

If microsoft-365 and the public result disagree

Check whether the edited zone is authoritative, whether the exact root/www/subdomain was changed, whether a proxy state alters the visible endpoint, and whether a prior TTL can still exist in recursive caches. Do not add a second conflicting find every v=spf1 TXT value to force validation.

Mistakes to avoid for this repair

Do not copy tenant-specific or region-specific values from another account, delete working email records during a website repair, change nameservers as a shortcut, or alter SSL/proxy modes without evidence from the origin. Add or fix Microsoft 365 SPF should change only the settings required by this diagnosis.

Technical references

These primary standards and provider documents are used to verify the behavior described on this page. Provider dashboards can change, so use the current official value for tenant-specific DNS records rather than copying an example from another account.