Back to Learning CenterEmail Authentication

What are Microsoft's new email authentication rules?

By Ian BussieresSeptember 29, 20252 min read
What are Microsoft's new email authentication rules?

Microsoft’s New Email Authentication Rules

Microsoft announced it will enforce the same email authentication standards that Google and Yahoo already require. This means every email sent to Outlook.com, Hotmail, or other Microsoft services must pass SPF, DKIM, and DMARC checks. The enforcement timeline is still “when, not if,” so preparing now is essential.

If your team is deciding whether to run this work itself or use outside help, see how to choose an email authentication service before assigning sender inventory, report review, and policy approval. Microsoft email authentication requirements

Key Requirements

  • All outbound mail must have valid SPF, DKIM, and DMARC records.
  • DMARC enforcement will move from “none” to “quarantine” or “reject” as providers roll out.
  • Maintain low spam complaint rates to protect sender reputation.

Why It Matters

These standards aim to stop phishing, spoofing, and fraudulent emails that damage brands and users. By adopting them, you improve deliverability and protect your reputation.

Steps to Get Ready

Five-step preparation flow: audit DNS records, check your Email Security Score, add BIMI, validate DKIM, and confirm SPF. Steps senders can take now, before Microsoft's enforcement begins.

At a glance

Quick Takeaways

  • Microsoft will enforce SPF, DKIM, and DMARC for all senders.
  • Enforcement timeline is “when, not if.”
  • DMARC will shift to quarantine/reject soon.
  • Low spam rates are essential for reputation.
  • Use Palisade tools to verify each authentication layer.

Additional Resources

Questions readers ask

Frequently Asked Questions

Check your domain against Microsoft’s sender requirements

Enter your domain.

Check Microsoft compliance

Keep going with AI

Ask AI how this applies to you

Take this guide to your assistant — each question opens pre-filled, with a link back to this page so it can read the details.

  • What are Microsoft's new email authentication rules?
  • How does this apply to my domain?
  • What should I do about it, step by step?

Share this article

Ian Bussieres

Written by

Ian Bussieres

CTO & Co-Founder, Palisade

Ian Bussieres is the CTO and co-founder of Palisade, AI-first DMARC software for IT teams and MSPs.

More from Ian

Related articles