Publish a TXT record at _dmarc.yourdomain.com: v=DMARC1; p=none; rua=mailto:[email protected]; fo=1. Microsoft 365 handles DMARC automatically on the sending side as long as SPF and DKIM are configured for your domain. Start at p=none for 4-8 weeks, review the RUA reports, then step up to p=quarantine and p=reject. If you use both Microsoft 365 and other senders (SendGrid, HubSpot, etc.), confirm all senders pass SPF alignment before moving to p=reject — otherwise legitimate mail bounces. Verify with the DMARC lookup tool.
All questions
How do I set up DMARC for Microsoft 365?
Read the full guide
What Is DMARC?
DMARC is the enforcement layer of email authentication. SPF and DKIM do the checking — DMARC tells receiving servers what to do when they fail, and reports back to you who's sending email using your domain.