SPF/DKIM Failures from External Sender to MS Outlook Hosted Domains

Liana Darbinyan 15 Reputation points
2025-05-23T05:59:35.41+00:00

We are a legitimate sender running our own mail server (not hosted on Microsoft 365), with proper SPF and DKIM configuration. In our DMARC reports, we’re seeing that some messages to recipients using Microsoft Outlook intermittently fail SPF or DKIM checks with temperror.

I have seen some threads on the case but no solution yet. Is there any kind of a solution to this, or approach where we can "whitelist" certain domains to avoid failures.

We’d like help understanding why Microsoft is intermittently marking these as failed and whether there's a cache or recipient-specific behavior involved.

Outlook | Windows | Classic Outlook for Windows | For business

5 answers

Sort by: Most helpful
  1. Matt Elvin 5 Reputation points
    2025-07-23T17:12:07.51+00:00

    This is a considerable problem. We provide DMARC services and this is happening over a number of our customers.

    The Microsoft response ranges from "not our fault, speak to your DNS provider" (all tested and verified good) and "change your TTL" (for reasons we've yet to hear them explain properly).

    This is clearly a problem with the MSFT lookup as it affects messages intermittently, DKIM config is verified good. We see similar behaviour with SPF and DMARC lookups, but again if you raise a support case there is a load of noise about how it's everybody else's fault and no ownership whatsoever.

    If they managed to convince anybody that they were a serious provider of secure email gateway services and that E5 is the answer to all problems, then you have my sympathy.

    @MSFT some ownership please.

    Was this answer helpful?

    2 people found this answer helpful.
    0 comments No comments

  2. Austin-H 8,355 Reputation points Microsoft External Staff Moderator
    2025-05-23T08:40:56.4766667+00:00

    Hi Liana Darbinyan  

    Thank you for contacting Microsoft Q&A Support. 

    Based on your description, I understand you're experiencing an issue where some of your emails to Outlook recipients are intermittently failing SPF or DKIM checks with "temp error". This can certainly be frustrating, especially when you've already configured SPF and DKIM correctly on your end. 

    To help us investigate this more thoroughly and provide you with the most accurate recommendations, could you please provide us with the message headers of some of the emails that failed these SPF or DKIM checks? Having this detailed information will allow us to analyze the exact error and pinpoint potential causes more effectively. 

    We understand that sharing message headers might be restricted due to your organization's security policies. If that's the case, we highly recommend raising a support ticket directly with Microsoft through your Admin Center. Our dedicated support team will have the tools and access necessary to investigate these intermittent failures on our end.  

    Link document: Get support - Microsoft 365 admin | Microsoft Learn 


    If this explanation is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".  

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread. 

    Was this answer helpful?

    1 person found this answer helpful.

  3. Deleted

    This answer has been deleted due to a violation of our Code of Conduct. The answer was manually reported or identified through automated detection before action was taken. Please refer to our Code of Conduct for more information.


    Comments have been turned off. Learn more

  4. Deleted

    This answer has been deleted due to a violation of our Code of Conduct. The answer was manually reported or identified through automated detection before action was taken. Please refer to our Code of Conduct for more information.


    Comments have been turned off. Learn more

  5. Laurent H 0 Reputation points
    2025-06-17T07:20:27.7133333+00:00

    The "académie de Strasbourg" has the same problem. Here is an example log :

    to=******@hotmail.fr, relay=eur.olc.protection.outlook.com[52.101.68.38]:25, delay=0.72, delays=0/0/0.25/0.46, dsn=5.7.515, status=bounced (host eur.olc.protection.outlook.com[52.101.68.38] said: 550 5.7.515 Access denied, sending domain AC-STRASBOURG.FR doesn't meet the required authentication level. The sender's domain in the 5322.From address doesn't meet the authentication requirements defined for the sender. To learn how to fix this see: https://go.microsoft.com/fwlink/p/?linkid=2319303 Spf= Pass , Dkim= Fail , DMARC= Pass [PR3P194MB0793.EURP194.PROD.OUTLOOK.COM 2025-06-17T07:10:31.483Z 08DDAD5ACDD20293] [DUZPR01CA0018.eurprd01.prod.exchangelabs.com 2025-06-17T07:10:31.501Z 08DDAA1B90B36004] [DU2PEPF00028D03.eurprd03.prod.outlook.com 2025-06-17T07:10:31.500Z 08DDA9D3319645CF] (in reply to end of DATA command))

    On the MECSA site (https://mecsa.jrc.ec.europa.eu/fr/), ac-strasbourg.fr seems to be OK regarding DKIM (report ID 0b75f1f85371d797d4509ba62a55fcbc).

    Was this answer helpful?


Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.