Microsoft 365 (formerly Office 365) recommends a simple SPF record that includes their sending infrastructure. However, many organizations use additional mail sources (marketing, transactional, ticketing). This tutorial shows how to publish a correct SPF record in Cloudflare, handle multiple senders, and validate alignment for DMARC.
For domains sending exclusively via Microsoft 365:
example.com. IN TXT "v=spf1 include:spf.protection.outlook.com -all"
The -all (hard fail) indicates that only listed mechanisms may send. If you are migrating, start with ~all (soft fail) temporarily while discovering all senders.
Include vendor-provided includes or IPs:
v=spf1 include:spf.protection.outlook.com include:_spf.yourvendor.com ip4:203.0.113.10 -all
include: over copying IP ranges; providers rotate IPs.SPF checks the envelope sender (return-path). To achieve DMARC alignment, ensure the organizational domain matches the visible From: address or use custom return-paths on non-Microsoft senders that align to your domain.
Received-SPF and Authentication-Results.include: and remove unused vendors.With a carefully designed SPF record and DKIM/DMARC alignment, Microsoft 365 domains maximize deliverability while preventing spoofed messages.