← Back to Blog
Cybersecurity

Microsoft 365 Emails Going to Junk? How to Fix It

3 October 2026 · By Ethan Fernandes

Microsoft 365 Emails Going to Junk? How to Fix It

Clients say your emails land in junk or spam, or you see "SPF fail" or "DMARC fail" in headers? Here's how to fix Microsoft 365 deliverability properly.

A client mentions your invoice was in their junk folder. Another says your quote never arrived, and it turns up weeks later in spam. If you look at the message headers on a test email to Gmail, you might see "spf=fail", "dkim=none" or "dmarc=fail", or Gmail shows a warning like "Be careful with this message".

When your emails go to junk, the receiving system doesn't trust that they really came from you. For a small business that means missed payments, lost quotes and clients thinking you've gone quiet. The fix is almost always in your domain's DNS and Microsoft 365 settings.

Quick answer

Make sure your domain has one correct SPF record that includes Microsoft 365, turn on DKIM signing for your domain in Microsoft Defender, and publish a DMARC record. Then check that every other service sending as your domain (invoicing, newsletters, CRM) is authenticated too, and test with a header check or a deliverability tool.

Why This Happens

Gmail, Outlook.com, Yahoo and corporate filters decide where your email goes based on several signals:

  • Authentication. SPF, DKIM and DMARC prove the message was sent by a server allowed to send for your domain. Since 2024, Google and Yahoo have required senders to authenticate properly, and missing records are a common reason for junking.
  • Reputation. If your domain or account has sent spam (for example, after a compromise), filters remember.
  • Content. Link shorteners, mismatched links, large attachments, all-image emails and certain file types raise suspicion.
  • Recipient behaviour. If people mark your emails as junk or never open them, filters learn from that.

Our explainer on SPF, DKIM and DMARC covers the theory. Here's the practical fix.

Step 1: Check What Recipients See

  1. Send a plain test email from Outlook to a personal Gmail account.
  2. In Gmail, open it, click the three dots and choose Show original. The top shows SPF, DKIM and DMARC as PASS or FAIL.
  3. Also try a free tool such as mail-tester.com, which gives a score and lists problems, or MXToolbox to look up your SPF and DMARC records.

If all three pass and you're still landing in junk, skip ahead to reputation and content.

Step 2: Fix Your SPF Record

SPF is a TXT record on your domain listing who can send as you. For Microsoft 365 only, it looks like:

v=spf1 include:spf.protection.outlook.com -all

  • You must have only one SPF record. Two separate v=spf1 records cause a permanent error. Merge them into one.
  • Add an include: for every other service that sends as your domain, using the value that service documents.
  • SPF has a limit of 10 DNS lookups. Too many includes break it. A record checker will tell you.
  • Use -all (fail) or ~all (soft fail) at the end, never +all.

Step 3: Turn On DKIM in Microsoft 365

DKIM adds a digital signature to every outgoing message. Microsoft 365 signs with its own onmicrosoft.com domain by default, which doesn't help your domain's reputation or DMARC. You need to enable it for your own domain.

For your Microsoft 365 admin

  1. Go to the Microsoft Defender portal (security.microsoft.com).
  2. Open Email & collaboration > Policies & rules > Threat policies and look for Email authentication settings, then the DKIM tab.
  3. Select your domain. The panel shows two CNAME records (selector1 and selector2). Copy them exactly as shown, because the format varies between tenants.
  4. Add both CNAMEs at your DNS host and wait for them to propagate.
  5. Return to the DKIM page and switch signing on.

In Exchange Online PowerShell you can check with Get-DkimSigningConfig and enable with Set-DkimSigningConfig -Identity yourdomain.co.uk -Enabled $true.

Step 4: Publish a DMARC Record

DMARC tells receivers what to do when SPF or DKIM fail, and sends you reports. Add a TXT record at _dmarc.yourdomain.co.uk. A safe starting point is:

v=DMARC1; p=none; rua=mailto:dmarc-reports@yourdomain.co.uk

Review the reports for a few weeks to find legitimate services that fail, fix them, then move to p=quarantine and eventually p=reject. A DMARC reporting service makes those reports readable.

Don't jump straight to p=reject. If your invoicing system or website contact form isn't authenticated yet, you'll block your own legitimate email.

Step 5: Authenticate Your Other Senders

The most common cause we see is a third-party system sending as your domain without permission: accounting software sending invoices, a CRM, an email marketing platform, a website form or a scanner relaying through an external server. Each one needs SPF and, ideally, DKIM set up for your domain using the records that provider documents. Where possible, send bulk marketing from a subdomain such as news.yourdomain.co.uk to protect your main domain's reputation.

Step 6: Check Reputation and Content

  • Search MXToolbox's blacklist check for your domain. If you've had a compromised account, see what to do when an account sends spam.
  • Avoid link shorteners and make sure link text matches the destination.
  • Share large files with a OneDrive or SharePoint link rather than big attachments, and avoid sending macro-enabled documents or zip files unexpectedly.
  • Keep signatures simple: one logo, no tracking pixels from free signature tools.
  • Ask key clients to add you to their safe senders list, and to mark your emails as Not junk, which helps their filter learn.

How to Stop It Happening Again

Deliverability isn't a one-off job. Every new app that sends email, every DNS change and every website rebuild can break authentication. Keep a list of everything that sends as your domain, monitor DMARC reports, and review them when you add a new system. Protecting accounts with MFA also protects your reputation, since a compromised mailbox spamming thousands of people is the quickest way to get blocked.

When to Call in Help

DNS changes are easy to get wrong and can break your email entirely. If you'd rather it was done once and monitored, our cybersecurity service sets up SPF, DKIM and DMARC and watches the reports, and our managed IT service covers your wider Microsoft 365 setup. Not sure where you stand? Try our free IT health check or get in touch.

Common questions

Most often because SPF, DKIM or DMARC isn't set up correctly for your domain, or another service sends as your domain without authentication. Check the message with Show original in Gmail to see which test fails.

In the Microsoft Defender portal, go to the threat policies area and open Email authentication settings, then DKIM. Publish the two CNAME records it shows for your domain, then switch signing on.

If Microsoft 365 is your only sender, v=spf1 include:spf.protection.outlook.com -all. Add includes for any other services that send as your domain, and keep it to a single SPF record.

Send a test to a tool like mail-tester.com, or to a Gmail account and use Show original to check SPF, DKIM and DMARC results. MXToolbox can also check your DNS records and blacklist status.

Want to talk about this?

Book a free 15-minute call and we'll discuss how this applies to your business.

Get IT tips in your inbox

Practical advice for small businesses. No spam.