SPF and DMARC records for microsoft.com
Live SPF and DMARC lookup for microsoft.com: the raw TXT records and the policy they enforce.
try:
- mail hosts
- microsoft-com.mail.protection.outlook.com
- provider
- microsoft
- spf record
- v=spf1 include:_spf-a.microsoft.com include:_spf-b.microsoft.com include:_spf-c.microsoft.com include:_spf-ssg-a.msft.net include:_spf1-meo.microsoft.com -all
- dmarc policy
- reject
- dmarc record
- v=DMARC1; p=reject; pct=100; rua=mailto:[email protected]; ruf=mailto:[email protected]; fo=1
- disposable domain
- no
- free consumer provider
- no
SPF for microsoft.com
microsoft.com publishes an SPF record; it authorises 5 included sender lists, and the record ends in -all (hard fail): mail from a server that is not listed should be rejected.
DMARC for microsoft.com
The DMARC policy for microsoft.com is p=reject: mail that fails SPF and DKIM alignment is refused outright. It is the strictest setting and the one Gmail and Yahoo now expect from bulk senders.
Why it matters
SPF says which servers may send as microsoft.com; DKIM signs the messages; DMARC tells receivers what to do when neither checks out and reports back to the owner. Together they decide whether mail from microsoft.com is trusted, and whether someone else can pretend to be microsoft.com. For verification they are a domain-quality signal: Spaw folds a missing SPF record into the risk score and reports has_spf and dmarc_policy on every email and domain lookup.
More checks for microsoft.com
checked 2026-09-03 · sources: live-dns 2026-09-03 · disposable-domains 2026-09-02 · free-provider-domains 2026-09-02 · mx-provider-patterns 2026-09-03 · rdap-registration 2026-09-03 · Top-domain list: Majestic Million, CC BY 3.0
Need this at scale?
The Spaw API runs the same checks plus mailbox-level SMTP verification, batch and bulk endpoints, and list monitoring — 10 free lookups a month, no card required.