Microsoft 365¶
Microsoft 365 here is just the mailbox. No Exchange server, no SharePoint site, no tenant to administer — one account that sends and receives mail for several domains. The only thing worth writing down is how to make that mail land in the recipient's inbox instead of their spam folder.
Aliases across multiple domains¶
One Microsoft account can send and receive for more than one domain. Add the extra domain under Settings → Domains, follow the DNS records (Cloudflare does this automatically), then add aliases from that domain to the main user under Users → Active users → Manage username and email.
I create aliases for the DMARC reports up front — dmarc-reports@ and dmarc-forensic@ — because you need them to exist before the records point at them.
Sending from an alias is a separate switch. It's easier through PowerShell than the admin portal:
Install-Module -Name ExchangeOnlineManagement
Connect-ExchangeOnline
Get-OrganizationConfig | ft Name, SendFromAliasEnabled
Set-OrganizationConfig -SendFromAliasEnabled $True
Then in Outlook, enable each alias individually under Mail → Compose and reply, and check Always show From so you can see which address you're actually sending as.
DKIM, DMARC, SPF¶
Microsoft does not enable DKIM for you. Go to the Defender portal, Policies & rules → Threat policies → Email authentication settings, and check the DKIM tab — your domains are probably showing as Disabled. Publish the two CNAMEs it gives you, wait ten minutes or so, then toggle it on. Now outgoing mail is signed with a private key and the public key is published as a DNS record for the receiving server to verify.
DMARC is a TXT record on _dmarc:
v=DMARC1; p=none; rua=mailto:[email protected]; ruf=mailto:[email protected]; pct=100
rua is the aggregate report — summarized authentication results. ruf is forensic — individual failures. Start at p=none and read the reports for three or four weeks. If legitimate mail is passing, move to p=quarantine, then p=reject. Going straight to reject is how you break your own mail.
SPF should already exist when the provider creates the mailbox — it lists which servers are allowed to send for the domain. Check it against the DKIM and DMARC status; a passing SPF with a failing DKIM alignment is the usual spam-folder story.
Full walkthrough: How to create trusted Emails.