SPF, DKIM and DMARC are correct all 7 of my domains, ONE will not send to outlook.com

2026-07-31T16:23:07.31+00:00

We have 7 domains from which we send hotel/resort checkin and reservations emails. SPF, DKIM, DMARC have been correctly set up on all domains, all verified with dig and MxToolBox. Only one of our domains, the most active [Moderator note: Personally Identifiable Information removed], have as of today begun to be rejected by hotmail and outlook.com with the following reject message:

host
outlook-com.olc.protection.outlook.com[[Moderator note: Personally Identifiable Information removed]] said: 550 5.7.515
Access denied, sending domain [Moderator note: Personally Identifiable Information removed] doesn't meet the required
authentication level. The sender's domain in the 5322.From address doesn't
meet the authentication requirements defined for the sender.

Again, MXToolBox, CloudFlare, every testing tool verifies SPF DKIM and DMARC are all valid. Which leads me to conclude there are some rules on the Microsoft side which applies only to the [Moderator note: Personally Identifiable Information removed] domain.

Outlook | Web | Outlook on the web for business | Email
0 comments No comments

1 answer

Sort by: Most helpful
  1. Chris Duong 10,620 Reputation points Microsoft External Staff Moderator
    2026-07-31T17:03:23.6633333+00:00

    Hi admin

    Good day. Thank you for sharing the details of your situation. 

    As a forum moderator, I genuinely wish I could directly access your account or review the backend systems to diagnose and resolve this issue for you. However, our role here is limited to providing general guidance by offering clear next steps, sharing applicable resources, and directing you to the appropriate support channels so you can work with the right team to investigate further. 

    Based on the NDR message, the key point is that the rejection is related to the domain in the 5322.From address, which is the visible From address used in the message. Even if the DNS records are valid, Microsoft evaluates the actual message when it reaches Outlook.com or Hotmail. This means the message must not only have valid SPF, DKIM, and DMARC records, but must also pass the required authentication and alignment checks for the From domain. 

    Since the affected domain appears to be the most active sending domain among the domains you mentioned, it may be the only one currently affected by stricter authentication enforcement, especially if it is sending a higher volume of messages to Microsoft consumer mailboxes. Other domains may not show the same behavior if their sending volume is lower or if their message streams are authenticating differently. 

    To continue troubleshooting, I recommend reviewing the full headers of an affected message, or a message from the same sending stream, and checking the following: 

    1/ Review the visible From domain and Return-Path 

    • Confirm that the visible From address uses the expected sending domain, as this is the 5322.From domain referenced in the bounce message.  
    • Also check the Return-Path, also known as the 5321.MailFrom or envelope sender. If SPF is being used to satisfy DMARC, the Return-Path domain should align with the visible From domain.  
    • SPF may pass for another sending domain, but it may not satisfy DMARC alignment for the domain shown in the From address. 

    2/ Check SPF, DKIM, and DMARC results in the message headers 

    • In the Authentication-Results, Received-SPF, and DKIM-Signature headers, confirm whether SPF, DKIM, and DMARC are passing on the actual message.  
    • The important point is not only whether SPF or DKIM passes, but whether at least one of them is aligned with the 5322.From domain so that DMARC passes for the visible From domain. 

    3/ Verify the DKIM signing domain 

    • Check the d= value in the DKIM-Signature header. Ideally, the message should be signed with the same domain as the visible From domain, or with an aligned subdomain.  
    • If the message is signed with a third-party provider’s domain, DKIM may still pass technically, but it may not be aligned with the From domain. 

    4/ Review all systems sending as the affected domain 

    • Also check all platforms that send email using the affected domain in the From address, such as reservation platforms, booking engines, CRM systems, marketing tools, website forms, SMTP relays, or other third-party services.  
    • It is possible for one sending source to be configured correctly while another sending source using the same From domain is not fully aligned. 

    For you reference, you may find these Microsoft articles helpful: 

    If you need further help with these steps, or if the message headers confirm that SPF, DKIM, and DMARC are all passing with proper alignment but the issue continues, I recommend opening a support ticket with Microsoft Support through the Microsoft 365 admin center. They may be able to review the affected domain and message details, provide guidance on the authentication results, and assist with any additional remediation steps. 

    I hope this helps clarify the situation. Should you have any further questions or need additional assistance, please feel free to share them in the comment below. I'm very happy to help.   

    Thank you again for your patience and understanding. 


    If the answer is helpful, please click "Yes" and kindly upvote it.Note: Follow the steps in our documentation to enable email notifications if you want to receive email notifications related to this topic.

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.