AgenorIT
AgenorIT
๐Ÿ›ก๏ธFree Microsoft 365 Cyber Tool

Microsoft 365 Email Security Checker

Check SPF, DKIM and DMARC for your domain in seconds, then get a plain-English plan to stop people spoofing your email.

Runs in your browser·Nothing stored·Free, no sign-up
Advanced options (Custom DKIM selectors, Transport Security)
Leave blank to automatically check default Microsoft 365 selectors (selector1, selector2) and common third-party senders.
๐Ÿ›ก๏ธ Verified Australian Reference Domain

Example: agenorit.com.au

Live DNS audit snapshot verified on 10 October 2026 via DNS-over-HTTPS.

95/100Strong
CheckRecord PublishedStatus & Result
Mail Host (MX)0 agenorit-com-au.mail.protection.outlook.com.โœ“ Pass: Microsoft 365
SPF Recordv=spf1 include:spf.protection.outlook.com include:resend.com ~allโœ“ Pass: Single valid record
SPF Lookupsoutlook.com (1) + resend.com (1) → _spf.google.com (+1)โœ“ Pass: 3 of 10 limit
SPF Qualifier~all (soft fail)โœ“ Pass: DMARC-ready
DKIM selector1CNAME → selector1-agenorit-com-au._domainkey.AgenorITServicesPtyLtd.p-v1.dkim.mail.microsoft.โœ“ Pass: Modern v1 target, key published
DKIM selector2CNAME → selector2-agenorit-com-au._domainkey.AgenorITServicesPtyLtd.p-v1.dkim.mail.microsoft.โœ“ Pass: Key published
DMARC Policyv=DMARC1; p=quarantine; rua=mailto:info@agenorit.com.au; aspf=r; adkim=rโœ“ Pass: Enforcing (quarantine, pct=100)
DMARC SubdomainsAbsent (implicit sp=quarantine)โ„น Info: Inherits apex policy
DMARC Reporting (rua)mailto:info@agenorit.com.auโœ“ Pass: Same-domain mailbox
Other SendersResend: include:resend.com; resend._domainkey key presentโ„น Info: Relaxed alignment covers send.agenorit.com.au
Advanced (MTA-STS, TLS-RPT, BIMI)MTA-STS, TLS-RPT, BIMI: none publishedโ„น Info: Optional post-reject hardening
โ„น
Recommended Rollout Step for agenorit.com.au: Steps 1โ€“7 are complete. Next: advance from p=quarantine to p=reject after review of daily reports confirms zero legitimate delivery failures.
๐Ÿ“– Technical Reference & Architecture

How Microsoft 365 email authentication works

Email was designed in an era of trust, so by default anyone can send messages spoofing your domain. Three DNS records resolve this, and Microsoft 365 natively supports each of them.

SPF (Sender Policy Framework) is a TXT record listing authorised mail servers. For Microsoft 365, it must include include:spf.protection.outlook.com, alongside external providers like CRM, invoicing, or website forms. SPF enforces a strict RFC 7208 10-lookup limit: each include, a, or mx tag recursively counts against this cap. Exceeding 10 lookups triggers a permanent failure (permerror), causing mail receivers to fail SPF across your entire domain.

DKIM (DomainKeys Identified Mail) appends cryptographic signatures to outgoing mail. Microsoft 365 configures two selectors, selector1 and selector2, published as CNAME records pointing to Microsoft-managed rotating keys. Publishing DNS CNAMEs is only step one: you must also manually toggle DKIM signing on within the Microsoft Defender Security Portal. Until activated, Microsoft signs outbound messages using its fallback onmicrosoft.com domain, preventing DMARC alignment.

DMARC (Domain-based Message Authentication, Reporting and Conformance) aligns SPF and DKIM with the visible From address, dictating receiver enforcement actions. While p=none only collects telemetry, p=quarantine routes suspicious mail to junk, and p=reject drops spoofed mail entirely. The mandatory rua tag directs receiving servers to send daily XML aggregate reports, revealing unaligned senders before enforcement.

The safe rollout path follows ACSC and Microsoft guidance:

  1. Publish SPF and Microsoft 365 DKIM CNAMEs.
  2. Activate DMARC at p=none with rua reporting.
  3. Analyse daily reports and align third-party SaaS senders.
  4. Transition to p=quarantine, then safely enforce p=reject.

For Australian organisations, this phased deployment typically spans four to eight weeks. Rushing straight to p=reject without report analysis is the most frequent cause of self-inflicted invoice delivery failures.

Client-side DNS inspection. This tool evaluates MX, SPF, DKIM, DMARC, and MTA-STS directly in your browser using Cloudflare and Google DNS-over-HTTPS. Your domain is never transmitted to, logged by, or retained on AgenorIT servers. It recursively counts SPF queries, validates modern Microsoft CNAME targets, identifies unaligned third-party hosts, and generates copy-paste DNS records.

Because DNS records display public configuration rather than live mail server dispatch, verify enforcement by sending a test message to an external inbox and inspecting the headers for spf=pass, dkim=pass, and dmarc=pass.

Why email authentication matters. Business email compromise remains Australia's most financially devastating cyber attack vector. Deploying authenticated SPF, DKIM, and DMARC protects brand reputation, satisfies corporate cyber insurance requirements, and directly aligns with ACSC Essential Eight maturity baselines.

Led by Gurinder Singh, a senior Azure architect, who brings in vetted specialists when a project needs them. AgenorIT helps Melbourne and Australian businesses configure Microsoft 365 email security properly the first time.

โ“ Frequently Asked Questions

Microsoft 365 Email Authentication FAQ

How do I check if DKIM is enabled for my Microsoft 365 domain?+

Look up the CNAME records selector1._domainkey and selector2._domainkey for your domain; this checker does it for you. If both point to Microsoft, the keys are published. Then confirm signing is switched on in the Microsoft Defender portal and send a test email: the headers should show dkim=pass for your own domain.

What is the SPF 10 DNS lookup limit?+

Receiving servers will only perform 10 DNS lookups while evaluating your SPF record. Every include, a, mx, exists and redirect counts, including those nested inside providers' own records. Going over the limit causes a permanent error, so SPF fails for all your mail. Remove unused services or use IP ranges to stay under ten.

How do I move DMARC from p=none to quarantine safely?+

Start with p=none and a rua reporting address, then review reports for two to four weeks. Make sure every legitimate sender passes SPF or DKIM aligned with your domain. Then switch to p=quarantine, optionally with pct=25 rising to 100, and move to p=reject once reports stay clean for about a month.

What DMARC record should a small Australian business use?+

Begin with v=DMARC1; p=none; rua=mailto:dmarc@yourdomain.com.au to collect reports without affecting delivery. Once Microsoft 365 DKIM is enabled and your other senders are aligned, change p=none to p=quarantine, then p=reject. Keep the rua address so you continue to see who is sending email using your domain.

Will a DMARC reject policy stop my invoices or newsletters?+

Only if those services send as your domain without passing aligned SPF or DKIM. Accounting, CRM and newsletter platforms usually support custom DKIM for your domain. Set that up during the monitoring phase, confirm they pass in your DMARC reports, and enforcement will block spoofed email while your legitimate messages keep arriving normally.

Does this checker store the domain I enter?+

No. The lookups run in your browser against Cloudflare's and Google's public DNS-over-HTTPS services, so the domain never reaches AgenorIT's servers. We don't log or store it. Like any DNS query, the DNS provider processes the request under its own privacy policy, and only public DNS records are read.

Professional Architecture & Hardening

Want this fixed properly, without breaking your invoices?

Led by Gurinder Singh, a senior Azure architect, who brings in vetted specialists when a project needs them. We set up SPF, DKIM and DMARC for Microsoft 365, find every sender, and take you to p=reject safely.

Senior Azure architect & vetted specialists · Strict confidentiality · Direct technical scoping