The Short Version
- Inventory every service that sends mail as your domain first; that list is the whole job.
- Publish one SPF record under ten lookups, then enable DKIM in Microsoft 365 and your other senders.
- Start DMARC at p=none to monitor, read the reports, and fix legitimate senders that fail.
- Ratchet DMARC to quarantine then reject, and SPF to -all, once your real mail passes.
Bottom line: An hour on SPF, DKIM, and DMARC makes your mail land and your domain hard to spoof.
Loading article…