Managing personal Outlook.com account settings, security, and privacy
Hello,
Starting May this year, Microsoft started mandating the configuration of SPF, DKIM and DMARC for high volume senders. See the blog post here: https://techcommunity.microsoft.com/blog/microsoftdefenderforoffice365blog/strengthening-email-ecosystem-outlook%E2%80%99s-new-requirements-for-high%E2%80%90volume-senders/4399730
These days, many businesses don’t send emails directly from the company that hosts their domain. Instead, they often use third-party services to send email on their behalf. For example, they might use Constant Contact to send newsletters, Square to send receipt and booking confirmation, or Salesforce to send customer service emails. If a company registers its domain (e.g., business.com) with Provider A but uses Provider B to send email on behalf of @business.com, then the company must add Provider B’s SPF, DKIM, and DMARC records into its DNS at Provider A. This ensures that when Provider B sends mail, the messages pass authentication checks and are not flagged as spoofed spam. Since May of this year, Microsoft has been enforcing strict SPF, DKIM, and DMARC checks for high-volume senders. If senders fail to configure these records properly, Microsoft may reject their incoming emails. In short, this issue must be fixed on the sender’s side, not Microsoft’s. Not all email service providers are mandating this as of today, and not all businesses are completely compliant with this requirement either.
If your gmail works fine for now, it is probably more practical to use your gmail for these use cases until more and more businesses are caught up with their SPF, DKIM and DMARC compliance. As of a matter of fact, more and more email service providers are moving to the direction of requiring these, simply because spoofing is a real threat and is getting more and more common, so there's no looking back unfortunately.