A cloud-based service included in Microsoft 365, delivering scalable messaging and collaboration features with simplified management and automatic updates.
Thanks for the clarification.
I don't have administrative access to the sender's Exchange Online tenant. I operate the email gateway on the forwarding path and am investigating a DMARC alignment issue observed downstream.
From the message headers we captured when the email first reaches our gateway, we see:
From: [email protected]
DKIM-Signature:
d=example.onmicrosoft.com
This DKIM signature authenticates successfully, but it does not align with the visible From domain example.com.
After the message is forwarded through our gateway, we use SRS, so SPF also passes authentication but the envelope sender uses our gateway domain. Therefore, SPF is no longer aligned with the original From domain either.
As a result, downstream receiving servers that enforce DMARC strictly can evaluate the forwarded message as DMARC fail and may quarantine it as spam or reject it.
We understand that signing with the onmicrosoft.com domain may be expected if DKIM for the custom domain is not enabled. However, we would like to understand whether there is a recommended configuration on the Microsoft 365 sender side that would allow the outbound message to carry a DKIM signature aligned with the custom From domain.
Could you please confirm:
- Is DKIM for the custom domain required/enabled on the sender's Microsoft 365 tenant to achieve DKIM alignment?
- If it is enabled, why would the outbound message still contain d=example.onmicrosoft.com?
- Is there any Microsoft-recommended approach for forwarded messages where SPF alignment is lost due to SRS, so that DMARC can still pass through downstream receiving servers?