---
title: "Outlook DMARC Requirements: Microsoft’s New Email Authentication Rules Explained | AutoSPF"
description: "Learn Microsoft’s Outlook DMARC requirements, including SPF, DKIM, DMARC alignment, DNS setup, enforcement, and best practices for email delivery."
image: "https://autospf.com/og/blog/outlook-dmarc-requirements-microsoft-s-new-email-authentication-rules-explained.png"
canonical: "https://autospf.com/blog/outlook-dmarc-requirements-microsoft-s-new-email-authentication-rules-explained/"
---

Quick Answer

Microsoft’s Outlook DMARC requirements ask high-volume senders to configure SPF and DKIM, publish a DMARC record, and maintain proper alignment. Monitoring DMARC reports helps identify authentication failures, protect domains, and support reliable email delivery.

## Try Our Free DMARC Checker

Validate your DMARC policy, check alignment settings, and verify reporting configuration.

[ Check DMARC Record → ](/tools/dmarc-checker/) 

Share 

[ ](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Fautospf.com%2Fblog%2Foutlook-dmarc-requirements-microsoft-s-new-email-authentication-rules-explained%2F "Share on LinkedIn") [ ](https://twitter.com/intent/tweet?text=Outlook%20DMARC%20Requirements%3A%20Microsoft%E2%80%99s%20New%20Email%20Authentication%20Rules%20Explained&url=https%3A%2F%2Fautospf.com%2Fblog%2Foutlook-dmarc-requirements-microsoft-s-new-email-authentication-rules-explained%2F "Share on X/Twitter") [ ](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fautospf.com%2Fblog%2Foutlook-dmarc-requirements-microsoft-s-new-email-authentication-rules-explained%2F "Share on Facebook") [ ](https://reddit.com/submit?url=https%3A%2F%2Fautospf.com%2Fblog%2Foutlook-dmarc-requirements-microsoft-s-new-email-authentication-rules-explained%2F&title=Outlook%20DMARC%20Requirements%3A%20Microsoft%E2%80%99s%20New%20Email%20Authentication%20Rules%20Explained "Share on Reddit") [ ](mailto:?subject=Outlook%20DMARC%20Requirements%3A%20Microsoft%E2%80%99s%20New%20Email%20Authentication%20Rules%20Explained&body=Check out this article: https%3A%2F%2Fautospf.com%2Fblog%2Foutlook-dmarc-requirements-microsoft-s-new-email-authentication-rules-explained%2F "Share via Email") 

![Outlook DMARC Authentication Requirements](https://media.mailhop.org/autospf/spf-record-checker-1017-1790247174015.jpg) 

## What Microsoft’s New Outlook DMARC Requirements Mean

Microsoft’s updated Outlook [email authentication](https://autospf.com/blog/safe-email-marketing-8-email-authentication-best-practices/) requirements reflect a broader industry shift toward stronger sender verification. For high-volume senders delivering email to Microsoft consumer services such as Outlook.com, Hotmail, Live.com, and MSN, Microsoft requires SPF and DKIM to be published and pass, a DMARC record to be published, and messages to pass **DMARC validation** through aligned SPF and/or DKIM.

_For organizations using Microsoft 365, Office 365, or third-party email platforms, understanding how SPF, DKIM, and DMARC work together is essential for meeting these requirements and reducing authentication-related delivery failures._

For high-volume senders delivering email to Outlook.com, Hotmail.com, Live.com, and other Microsoft consumer email services, maintaining valid email authentication is essential. Microsoft requires these senders to have SPF and DKIM configured and passing, publish a DMARC record, and meet DMARC alignment requirements. The DMARC policy is published as a [DNS TXT record](https://efficientip.com/glossary/dns-txt-record/) at the `_dmarc` hostname for the sending domain.

DMARC, defined in **RFC 7489**, helps receiving mail systems verify whether a message is legitimately associated with the domain shown in the visible From address. It strengthens email security by helping protect users from phishing, [business email compromise](https://www.cybersecuritydive.com/news/fbi-internet-crime-bec-scams-investment-fraud-losses/746181/), and email spoofing.

### Microsoft’s Authentication Requirements for High-Volume Senders

Microsoft’s Outlook requirements place greater emphasis on authenticated email for **high-volume senders**. For senders subject to these requirements, SPF and DKIM must be published and pass, a DMARC record must be published, and DMARC must pass through aligned SPF and/or DKIM.

Key authentication requirements include:

- **SPF:** Publish an SPF record that authorizes the servers and services sending email for the domain.
- **DKIM:** Enable DKIM signing so outbound messages can be authenticated using a public key published in DNS.
- **DMARC:** Publish a DMARC TXT record at the `_dmarc` hostname.
- **DMARC alignment:** Ensure that either the SPF-authenticated domain or DKIM signing domain aligns with the domain in the visible From address.
- **DMARC monitoring:** Review aggregate **DMARC reports** to identify legitimate senders, authentication failures, and potential unauthorized sources.

These requirements can apply to organizations sending through Microsoft 365, Office 365, SMTP relays, marketing platforms, [CRMs](https://www.coursera.org/articles/what-is-a-crm), and other third-party email services when they meet Microsoft’s high-volume sender criteria.

### What Enforcement Looks Like for Outlook Senders

![Spf Flattening 8505](https://media.mailhop.org/autospf/spf-flattening-8505-1790247866488.jpg)For high-volume senders that do not meet Microsoft’s email authentication requirements, messages may be rejected. Microsoft documents the [550 5.7.515 error](https://www.uriports.com/blog/outlook-error-550-5-7-515-and-how-to-fix-it/) for messages from domains that fail to meet the required authentication level. Meeting SPF, DKIM, and DMARC requirements can help senders avoid authentication-related rejection when delivering mail to **Microsoft consumer email services**.

A DMARC policy tells receivers what to do when DMARC validation fails. The three core policy options are:

#### DMARC Policy Actions: None, Quarantine, and Reject

- `p=none`: Monitor-only mode. Mail is not blocked solely because of the DMARC policy, but reports are generated.
- `p=quarantine`: Failing messages should be treated as suspicious and may go to spam or junk.
- `p=reject`: Failing messages should be rejected outright.

Starting with `p=none` can be a useful approach, while mature domains should move toward `p=quarantine` or `p=reject` after confirming that all **legitimate mail** streams are properly aligned.

## Why DMARC, SPF, and DKIM Matter for Outlook Deliverability

[DMARC](https://autospf.com/blog/mailgun-dmarc-setup-guide-configuring-spf-dkim-and-dmarc-correctly/), SPF, and DKIM work together to help Microsoft distinguish legitimate mail from abuse. SPF verifies whether the sending IP address is authorized to send for a domain. DKIM verifies that the message was signed by an authorized domain and was not materially altered in transit. DMARC connects SPF and DKIM to the visible From address that users actually see in their email client.

For Outlook deliverability, this combined authentication matters because Microsoft Defender for Office 365, **Microsoft Security systems**, and Outlook filtering evaluate multiple trust signals. Strong email authentication improves the likelihood that legitimate messages reach the inbox, while weak authentication increases the risk of filtering.

Organizations that care about [email security](https://autospf.com/) should treat DMARC, SPF, and DKIM as foundational controls rather than compliance checkboxes.

### SPF and DKIM as the Foundation

SPF depends on a properly published SPF record in DNS. This record lists the mail servers or services permitted to send on behalf of a domain. _For example, a company using Microsoft 365, Office 365, and a marketing platform must ensure all authorized outbound mail sources are included without exceeding SPF lookup limits._

DKIM uses public-private key cryptography. The sending service signs messages with a [private key](https://www.techtarget.com/cybersecurity/definition/What-is-a-private-key), and the receiving server checks the DKIM signature against a [public key](https://www.investopedia.com/terms/p/public-key.asp) stored in DNS. In Microsoft 365, DKIM signing can be enabled through the Microsoft 365 admin center or PowerShell. Microsoft typically uses DKIM selectors, often referenced as selector records, to locate the correct **DKIM key**.![Spf Lookup 3039](https://media.mailhop.org/autospf/spf-lookup-3039-1790248063805.jpg)

### How DMARC Validation Connects SPF and DKIM

DMARC validation passes when either SPF or DKIM passes and the authenticated domain aligns with the visible From address domain. Alignment is the key concept. SPF may authenticate the mail from the address, also called the envelope sender, while DKIM authenticates the signing domain. DMARC checks whether one of those authenticated domains matches the organizational domain in the From address.

#### Alignment Is What Makes DMARC Different

A message can technically pass SPF but still fail DMARC if the SPF-authenticated domain does not align with the From address. Similarly, a [DKIM signature](https://docs.mapp.com/docs/dkim-signature) from a third-party domain may pass DKIM but fail DMARC alignment if it does not match your domain.

##### Example: contoso.com and Microsoft 365

If a company sends as `user@contoso.com` through Microsoft 365, the domain `contoso.com` should have SPF, DKIM, and a DMARC TXT record. If the tenant also has `contoso.onmicrosoft.com`, that onmicrosoft.com domain may be part of Microsoft’s default routing, but the [custom domain](https://www.contentstack.com/docs/launch/custom-domain) shown to recipients still needs its own DNS configuration for **DMARC, SPF, and DKIM**.

## Who Is Affected by the Updated Outlook Email Authentication Rules

_The updated Outlook email authentication rules affect any sender delivering mail to Microsoft-hosted consumer recipients and, indirectly, many business environments using Microsoft 365 and Office 365 filtering._ High-volume senders are the clearest target, but smaller organizations are also affected because **Outlook’s filtering systems** increasingly rely on authentication signals.

### Organizations Using Microsoft 365, Office 365, and Custom Domains

Businesses using custom domains in Microsoft 365 or Office 365 need to verify that each domain has correct [DNS records](https://www.digicert.com/faq/dns/what-are-dns-records). This includes primary domains, aliases, parked domains used for [outbound mail](https://www.ricoh-usa.com/en/glossary/outbound-mail), and subdomains used by departments or applications.

Affected senders include:

- Companies sending invoices, alerts, or notifications from Microsoft 365.
- Marketing teams using third-party platforms with a company domain.
- SaaS products sending email on behalf of customers.
- Organizations using **SMTP relays** or hybrid Exchange environments.
- Security-conscious teams managing Microsoft Defender for Office 365.
- Domains listed in the Microsoft 365 admin center under the Domains page.![Spf Record Checker 1530](https://media.mailhop.org/autospf/spf-record-checker-1530-1790248100837.jpg)If you send as `contoso.com`, Microsoft expects authentication for `contoso.com`, not just proof of domain ownership in the Admin portal. Proof of domain ownership is required to add a domain to Microsoft 365, but it is not the same as having complete SPF, DKIM, and DMARC.

## How to Set Up or Update DMARC for Outlook Compliance

Setting up DMARC for Outlook compliance requires careful coordination between DNS, Microsoft 365, Office 365, and any third-party senders. _The goal is to publish a correct DMARC TXT record, ensure SPF and DKIM are working, and monitor reports before moving to stricter enforcement._

### Step-by-Step DNS and Microsoft 365 Configuration

Start by identifying every service that sends outbound mail using your domain. This includes **Microsoft 365, Office 365**, marketing platforms, [ticketing tools](https://www.kahunacrm.com/en/magazine/freshdesk-en/ticketing-tools-what-are-they-for/), billing systems, and internal applications.

Then follow these steps:

1. **Review SPF in DNS**Confirm your SPF record includes Microsoft 365 and all authorized senders. A common Microsoft 365 SPF entry includes `include:spf.protection.outlook.com`, but your exact SPF record depends on your [mail routing](https://www.cloudflare.com/learning/email-security/what-is-email-routing/).
2. **Enable DKIM signing**In the Microsoft 365 admin center, go to the appropriate DKIM settings for your domain. You may need to create [CNAME records](https://support.dnsimple.com/articles/cname-record/) for each selector at your DNS hosting service. DKIM signing should be active for the custom domain, not only the default onmicrosoft.com address.
3. **Create the DMARC TXT record**At your domain registrar or [DNS hosting provider](https://www.ntchosting.com/encyclopedia/dns/hosting/), create a TXT record named `_dmarc`. A monitoring-mode DMARC TXT record may look like:

```
v=DMARC1; p=none; rua=mailto:dmarc-aggregate@contoso.com; ruf=mailto:dmarc-forensic@contoso.com
```

1. **Add reporting addresses**The `rua` tag defines the report **URI for aggregate reports**. The `ruf` tag defines the report URI for forensic reports, though not all receivers send forensic reports due to privacy concerns.
2. **Analyze DMARC reports**Use DMARC reports to identify legitimate and unauthorized senders. Some teams process these reports with [Power BI](https://www.techtarget.com/enterprise-software/definition/What-is-Microsoft-Power-BI-Uses-features-and-guide) for visibility across domains, subdomains, sources, and authentication results.
3. **Move toward enforcement**After confirming legitimate mail passes DMARC validation, update the **DMARC policy** from `p=none` to `p=quarantine`, and eventually to `p=reject` where appropriate.

_Microsoft 365 administrators can also use PowerShell and the Admin portal to review domain status, DKIM configuration, and mail flow behavior._ ![Spf Lookup 6036](https://media.mailhop.org/autospf/spf-lookup-6036-1790246283800.jpg)

## Common DMARC Mistakes and Best Practices for Staying Compliant

Even organizations with mature IT teams often make DMARC mistakes. The most common issue is publishing a DMARC policy before SPF and DKIM are fully aligned. Another frequent problem is assuming that Microsoft 365 automatically handles all DNS records for every domain. Microsoft provides the email platform, but the domain owner is responsible for **DNS accuracy**.

### Mistakes That Break Authentication or Delivery

Common mistakes include:

- Publishing multiple [SPF records](https://autospf.com/blog/spf-records-in-dns-a-complete-guide-for-email-security/) for one domain instead of a single combined SPF record.
- Forgetting to enable DKIM signing for custom domains in Microsoft 365 or Office 365.
- Creating the DMARC TXT record at the wrong DNS hostname, such as the root domain instead of `_dmarc`.
- Using `p=reject` too early and blocking legitimate mail.
- Ignoring subdomains that send application or [transactional mail](https://www.activecampaign.com/glossary/transactional-email).
- Failing to align the DKIM signing domain with the visible From address.
- Not monitoring aggregate reports after publishing a DMARC policy.
- Assuming `onmicrosoft.com` authentication **protects all branded mail** from a custom domain.

Best practices include starting with `p=none`, validating all outbound email sources, reviewing DMARC reports regularly, and gradually moving to `p=quarantine` and then `p=reject`. Organizations with **complex email environments** should also document sending services, monitor authentication alignment, and use ARC where appropriate to support message authentication across trusted forwarding paths.

ARC, or [Authenticated Received Chain](https://systron.net/blog/understanding-authenticated-received-chain-arc-benefits-drawbacks-implementation-and-use-cases-for-email-authentication/), may also matter when messages are forwarded through intermediaries. _An ARC sealer can preserve authentication context when mail is forwarded, although ARC does not replace DMARC, SPF, or DKIM._

Ultimately, Outlook DMARC compliance depends on maintaining accurate DNS, a valid **DMARC TXT record**, correct SPF and DKIM configuration, and a DMARC policy that reflects the real state of your email system.

![Brad Slavin](https://media.mailhop.org/autospf/images/authors/brad-slavin.jpg) 

[ Brad Slavin ](/authors/brad-slavin/) 

General Manager

Founder and General Manager of DuoCircle. Product strategy and commercial lead for AutoSPF's 2,000+ customer base.

[LinkedIn Profile →](https://www.linkedin.com/in/bradslavin) 

## Ready to get started?

Try AutoSPF free — no credit card required.

[ Book a Demo ](/book-a-demo/) 

Scan Your Domain Now

Instantly scan your domain for DKIM, SPF, and DMARC issues

Check My Domain 

Share this article

[ ](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Fautospf.com%2Fblog%2Foutlook-dmarc-requirements-microsoft-s-new-email-authentication-rules-explained%2F) [ ](https://twitter.com/intent/tweet?text=Outlook%20DMARC%20Requirements%3A%20Microsoft%E2%80%99s%20New%20Email%20Authentication%20Rules%20Explained&url=https%3A%2F%2Fautospf.com%2Fblog%2Foutlook-dmarc-requirements-microsoft-s-new-email-authentication-rules-explained%2F) [ ](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fautospf.com%2Fblog%2Foutlook-dmarc-requirements-microsoft-s-new-email-authentication-rules-explained%2F) Copy 

Related Articles

- [ ![DIY-ing SPF](https://media.mailhop.org/autospf/images/2024/04/spf-record-example-5874.jpg)  10 Reasons Why DIY-ing SPF isn’t a Good Choice for Companies Intermediate ](/blog/10-reasons-diy-ing-spf-isnt-good-choice-for-companies/)
- [ ![phishing actors](https://media.mailhop.org/autospf/images/2025/11/spf-record-checker-0096.jpg)  The 12.4 billion shield for your email communications: Why DMARC software is the unsung hero in the war against phishing actors! Intermediate ](/blog/12-4-billion-dmarc-software-shield-protecting-email-from-phishing-actors/)
- [ ![421 Error SMTP Guide](https://media.mailhop.org/autospf/spf-lookup-1607-1785756872932.jpg)  421 Error SMTP Survival Guide: Fix the 4.4.2 Connection Dropped Issue Intermediate ](/blog/421-error-smtp-survival-guide-fix-connection-dropped-email-issue/)
- [ ![Sender Policy Framework](https://media.mailhop.org/autospf/images/2024/11/spf-checker-4785.jpg)  5 key contributors to the development of the Sender Policy Framework Intermediate ](/blog/5-key-contributors-to-sender-policy-framework-development/)

## Related Articles

[  Intermediate 6m  10 Reasons Why DIY-ing SPF isn’t a Good Choice for Companies  Apr 4, 2024 ](/blog/10-reasons-diy-ing-spf-isnt-good-choice-for-companies/)[  Intermediate 5m  The 12.4 billion shield for your email communications: Why DMARC software is the unsung hero in the war against phishing actors!  Nov 19, 2025 ](/blog/12-4-billion-dmarc-software-shield-protecting-email-from-phishing-actors/)[  Intermediate  421 Error SMTP Survival Guide: Fix the 4.4.2 Connection Dropped Issue  Aug 3, 2026 ](/blog/421-error-smtp-survival-guide-fix-connection-dropped-email-issue/)[  Intermediate 3m  5 key contributors to the development of the Sender Policy Framework  Nov 12, 2024 ](/blog/5-key-contributors-to-sender-policy-framework-development/)

```json
{"@context":"https://schema.org","@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com","logo":{"@type":"ImageObject","url":"https://autospf.com/images/autospf-logo.png"},"description":"Automatic SPF flattening and email authentication management. Resolve SPF lookup limits, flatten SPF records, and maintain email deliverability across all your domains.","parentOrganization":{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138883901","name":"DuoCircle LLC","url":"https://www.duocircle.com","sameAs":["https://www.wikidata.org/wiki/Q138883901","https://www.crunchbase.com/organization/duocircle-llc","https://www.linkedin.com/company/duocircle","https://github.com/duocircle"],"subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"sameAs":["https://www.wikidata.org/wiki/Q138897474","https://www.linkedin.com/company/autospf","https://x.com/autospf01","https://www.g2.com/products/autospf/reviews"],"contactPoint":{"@type":"ContactPoint","contactType":"customer support","url":"https://autospf.com/contact-us/"},"knowsAbout":["SPF Record Flattening","Sender Policy Framework","Email Authentication","DNS Management","DMARC","DKIM"]}
```

```json
{"@context":"https://schema.org","@type":"WebSite","name":"AutoSPF","url":"https://autospf.com","description":"Automatic SPF flattening and email authentication management. Resolve SPF lookup limits, flatten SPF records, and maintain email deliverability across all your domains.","publisher":{"@type":"Organization","name":"AutoSPF","url":"https://autospf.com","logo":{"@type":"ImageObject","url":"https://autospf.com/images/autospf-logo.png"},"description":"Automatic SPF flattening and email authentication management. Resolve SPF lookup limits, flatten SPF records, and maintain email deliverability across all your domains.","parentOrganization":{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138883901","name":"DuoCircle LLC","url":"https://www.duocircle.com","sameAs":["https://www.wikidata.org/wiki/Q138883901","https://www.crunchbase.com/organization/duocircle-llc","https://www.linkedin.com/company/duocircle","https://github.com/duocircle"],"subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]}}}
```

```json
{"@context":"https://schema.org","@type":"BlogPosting","headline":"Outlook DMARC Requirements: Microsoft’s New Email Authentication Rules Explained","description":"Learn Microsoft’s Outlook DMARC requirements, including SPF, DKIM, DMARC alignment, DNS setup, enforcement, and best practices for email delivery.","url":"https://autospf.com/blog/outlook-dmarc-requirements-microsoft-s-new-email-authentication-rules-explained/","datePublished":"2026-09-24T00:00:00.000Z","dateModified":"2026-09-24T00:00:00.000Z","dateCreated":"2026-09-24T00:00:00.000Z","author":{"@type":"Person","@id":"https://autospf.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://autospf.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin is the founder and General Manager of DuoCircle, the company behind AutoSPF, DMARC Report, Phish Protection, and Mailhop. He founded DuoCircle in 2014 to solve the SPF 10-DNS-lookup problem at scale and has led the company's growth to 2,000+ customers. Brad's focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement) rather than hands-on DNS engineering.","image":"https://media.mailhop.org/autospf/images/authors/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"AutoSPF","url":"https://autospf.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com","logo":{"@type":"ImageObject","url":"https://autospf.com/images/autospf-logo.png"},"description":"Automatic SPF flattening and email authentication management. Resolve SPF lookup limits, flatten SPF records, and maintain email deliverability across all your domains.","parentOrganization":{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138883901","name":"DuoCircle LLC","url":"https://www.duocircle.com","sameAs":["https://www.wikidata.org/wiki/Q138883901","https://www.crunchbase.com/organization/duocircle-llc","https://www.linkedin.com/company/duocircle","https://github.com/duocircle"],"subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"sameAs":["https://www.wikidata.org/wiki/Q138897474","https://www.linkedin.com/company/autospf","https://x.com/autospf01","https://www.g2.com/products/autospf/reviews"],"contactPoint":{"@type":"ContactPoint","contactType":"customer support","url":"https://autospf.com/contact-us/"},"knowsAbout":["SPF Record Flattening","Sender Policy Framework","Email Authentication","DNS Management","DMARC","DKIM"]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://autospf.com/blog/outlook-dmarc-requirements-microsoft-s-new-email-authentication-rules-explained/"},"articleSection":"intermediate","keywords":"","image":{"@type":"ImageObject","url":"https://media.mailhop.org/autospf/spf-record-checker-1017-1790247174015.jpg","caption":"Outlook DMARC Authentication Requirements"},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}}
```

```json
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://autospf.com/"},{"@type":"ListItem","position":2,"name":"Blog","item":"https://autospf.com/blog/"},{"@type":"ListItem","position":3,"name":"Intermediate","item":"https://autospf.com/intermediate/"},{"@type":"ListItem","position":4,"name":"Outlook DMARC Requirements: Microsoft’s New Email Authentication Rules Explained","item":"https://autospf.com/blog/outlook-dmarc-requirements-microsoft-s-new-email-authentication-rules-explained/"}]}
```
