Skip to main content
EmailToolBox LogoEmailToolBox
HomeAll ToolsSuper Lookup
Email Health CheckEmail DeliverabilityEmail Blacklist CheckerEmail Header AnalyzerSPF CheckerDKIM CheckerDMARC CheckerMX Lookup
View All Tools
SPF CheckerDKIM CheckerDMARC CheckerSPF GeneratorDMARC GeneratorBIMI CheckerMTA-STS Checker
Guides
中文

Related Tools

MX Lookup
Check mail servers
Email Blacklist Checker
Check IP reputation
DNS Lookup
DNS record queries
SPF Checker
Validate SPF records
DMARC Checker
Check and analyze DMARC records
Email Header Analyzer
Analyze email headers
DKIM Checker
Verify DKIM signatures
WHOIS Lookup
Domain registration info
SMTP Test
Test SMTP connectivity
SSL Certificate Lookup
Check SSL certificates
DNS Propagation Checker
Check DNS propagation
Ping Test
Test network connectivity
Traceroute
Trace network path
Subnet Calculator
Calculate IP subnets
What Is My IP
Check your IP address

Need Help?

Our tools are designed to be intuitive, but if you need assistance, we're here to help.

DocumentationContact Support

About Our Tools

Professional-grade email and DNS diagnostic tools trusted by IT professionals worldwide.

Free to UseNo RegistrationReal-time Results
EmailToolBox LogoEmailToolBox

EmailToolBox is a free suite of email testing, deliverability and domain diagnostics tools. Check your email health, validate SPF/DKIM/DMARC, look up DNS records and monitor blacklist status in seconds - no signup required.

  • Free to use
  • No signup required
  • Instant results
  • Real-time DNS checks
  • Privacy-focused

Email Diagnostics

  • Email Health Check
  • Email Deliverability
  • Email Blacklist Checker
  • Email Header Analyzer
  • Email Verifier
  • HTML Email Validator
  • Email Preview Simulator
  • Spam Test
  • Email Health Report

Email Authentication

  • SPF Checker
  • DKIM Checker
  • DMARC Checker
  • DMARC Report Analyzer
  • SPF Generator
  • DMARC Generator
  • BIMI Checker
  • MTA-STS Checker

DNS & Infrastructure

  • MX Lookup
  • DNS Lookup
  • TXT Record Lookup
  • CNAME Record Lookup
  • NS Lookup
  • DNS Propagation
  • PTR/rDNS Record Lookup
  • SMTP Test
  • WHOIS Lookup

Resources

  • Email Guides
  • All Tools
  • FAQ
  • Contact Us
  • About
  • Privacy Policy
  • Terms of Service

Friend Links

  • Favicon Generator
  • Email Testing tools
  • Morse Code Translator
  • Password Remover
  • Regex Cheat Sheet
  • free barcode generator
  • Free Online PDF Tools
  • fast chart
  • refnet
  • world market hours

© 2026 EmailToolBox - Email Testing, Deliverability & Domain Diagnostics. All rights reserved.

    1. Home
    2. Guides
    3. Azure SPF Configuration Tutorial
    Categories
    Related Guides

    Office 365 DKIM Setup Guide

    Detailed steps for configuring DKIM signatures in Microsoft Office 365

    AWS DKIM Configuration Tutorial

    Enable DKIM for Amazon SES and publish DNS records

    Mailgun SPF and DKIM Setup

    Configure SPF and DKIM for Mailgun to authenticate sending

    Azure SPF Configuration Tutorial

    Publish SPF records for Azure/Microsoft 365 sending services
    1 min read
    Updated 2025-10-22
    Brand Specific
    azurespfm365dns

    Azure SPF Configuration Tutorial

    Microsoft 365 (formerly Office 365) recommends a simple SPF record that includes their sending infrastructure. However, many organizations use additional mail sources (marketing, transactional, ticketing). This tutorial shows how to publish a correct SPF record in Cloudflare, handle multiple senders, and validate alignment for DMARC.

    Base SPF Record

    For domains sending exclusively via Microsoft 365:

    example.com. IN TXT "v=spf1 include:spf.protection.outlook.com -all"
    

    The -all (hard fail) indicates that only listed mechanisms may send. If you are migrating, start with ~all (soft fail) temporarily while discovering all senders.

    Adding Other Providers

    Include vendor-provided includes or IPs:

    v=spf1 include:spf.protection.outlook.com include:_spf.yourvendor.com ip4:203.0.113.10 -all
    
    • Prefer vendor-managed include: over copying IP ranges; providers rotate IPs.
    • Keep total DNS mechanisms under 10 to avoid SPF permerror (too many lookups).

    MAIL FROM and Alignment

    SPF checks the envelope sender (return-path). To achieve DMARC alignment, ensure the organizational domain matches the visible From: address or use custom return-paths on non-Microsoft senders that align to your domain.

    Publishing in Cloudflare

    1. Open your zone and add a TXT record on the root (or specific subdomain).
    2. Paste the complete SPF value exactly as a single string.
    3. Use a short TTL during changes; increase after stable.

    Validation

    • Send test emails and check headers for Received-SPF and Authentication-Results.
    • Use online SPF evaluators to confirm there are fewer than 10 DNS lookups.
    • For forwarding paths, rely on DKIM for DMARC alignment if SPF fails.

    Common Pitfalls

    • Duplicate SPF records: only one TXT SPF record should exist per domain.
    • Overlong records: use include: and remove unused vendors.
    • HELO identity issues: ensure your outbound systems present correct HELO/EHLO names, especially for on-prem relays.

    With a carefully designed SPF record and DKIM/DMARC alignment, Microsoft 365 domains maximize deliverability while preventing spoofed messages.

    Was this guide helpful?

    Azure SPF Configuration Tutorial - EmailToolBox