Find the error you’re seeing below. Each guide explains what the error means and what to change, and most check your domain’s DNS records right in your browser. Nothing to install, no sign-up.
Your domain doesn’t meet Microsoft’s authentication level for high-volume senders: it needs passing SPF, DKIM and a DMARC record.
The message failed DMARC and your own domain’s policy asks receivers to reject it. Usually one sender isn’t aligned.
The IP that delivered your mail has no reverse DNS, or its PTR hostname doesn’t resolve back to it. Check the IP and get the PTR fixed at its owner.
Two v=spf1 records on one name make SPF fail for every message. Get one merged record with its lookup count.
SPF stops at 10 DNS lookups and returns PermError. How nested includes count and how to get back under the limit; the DMARC checker counts yours.
More than one record at _dmarc means receivers apply no DMARC policy. Get a single merged record.
Check your selector1 and selector2 CNAMEs against what Microsoft expects, including the newer target format.
Run the free DMARC, SPF and DKIM checker for an A–F grade of one domain, or read the Gmail, Yahoo and Microsoft bulk sender requirements. To check hundreds of domains at once, use Email Security Signals on Apify.