{"id":21361,"date":"2026-02-12T06:43:51","date_gmt":"2026-02-12T05:43:51","guid":{"rendered":"https:\/\/coreit.se\/okategoriserad\/how-does-spf-work-in-microsoft-365"},"modified":"2026-03-26T07:26:02","modified_gmt":"2026-03-26T06:26:02","slug":"how-does-spf-work-in-microsoft-365","status":"publish","type":"post","link":"https:\/\/coreit.se\/en\/faq\/how-does-spf-work-in-microsoft-365","title":{"rendered":"How does SPF work in Microsoft 365?"},"content":{"rendered":"\n<div class=\"custom-ai-wrapper\">\n  <h2 class=\"ai-question\">How SPF works in Microsoft 365 &#8211; protection against email spoofing<\/h2>\n\n  <div class=\"ai-summary\">\n    <p>The Sender Policy Framework (SPF) in Microsoft 365 helps prevent unauthorized people from sending emails in the company&#8217;s name. By defining which servers are allowed to send email for the domain, receiving systems can verify that the sender is legitimate. Together with DMARC and DKIM, SPF strengthens email security, reduces the risk of spam and phishing, and protects your company&#8217;s reputation.  <\/p>\n  <\/div>\n\n  <div class=\"ai-columns\">\n    <div class=\"ai-background\">\n      <h2>Background and overview<\/h2>\n      <p>SPF is an email security standard that helps verify that incoming messages come from authorized sources. In Microsoft 365, SPF is used as part of a broader strategy to protect against email spoofing and phishing attacks. <\/p>\n\n      <h3>What is SPF?<\/h3>\n      <p>Sender Policy Framework (SPF) is a DNS-based method that specifies which mail servers are allowed to send email for a given domain.<\/p>\n\n      <h3>How SPF works in practice<\/h3>\n      <p>When an email is received, the receiving server checks the SPF record for the domain. If the sender&#8217;s server is not authorized, the message is marked as potentially false. <\/p>\n\n      <h3>SPF and Microsoft 365<\/h3>\n      <p>Microsoft 365 automatically provides SPF records for domains that use the service. Administrators can customize the SPF record to include third-party providers that send email for the company. <\/p>\n\n      <h3>Benefits of the SPF<\/h3>\n      <p>SPF reduces the risk of phishing and spam, protects your company&#8217;s brand and improves the deliverability of legitimate email.<\/p>\n\n      <h3>SPF together with DKIM and DMARC<\/h3>\n      <p>Together with DKIM (digital signature) and DMARC (policy and reporting), SPF contributes to strong email authentication and reduces the risk of forged messages.<\/p>\n\n      <h3>Implementation and monitoring<\/h3>\n      <p>Administrators should regularly review and update SPF records, monitor reports, and ensure that changes to third-party servers are accurately reflected.<\/p>\n\n      <h3>Common mistakes<\/h3>\n      <p>Common errors include not including all email sources, overly long SPF records, or syntactic errors that can cause legitimate messages to be flagged.<\/p>\n    <\/div>\n\n    <div class=\"ai-right\">\n      <div class=\"ai-details\">\n        <h2>Key points about SPF in Microsoft 365<\/h2>\n        <ul>\n          <li><strong>DNS-based verification:<\/strong> Specifies which servers are allowed to send emails for the domain.<\/li>\n          <li><strong>Anti-spoofing protection:<\/strong> Reduces phishing and spam.<\/li>\n          <li><strong>Integration with Microsoft 365:<\/strong> SPF records are automatically created but can be customized.<\/li>\n          <li><strong>In conjunction with DKIM and DMARC:<\/strong> Enhances email security and delivery reliability.<\/li>\n          <li><strong>Regular monitoring:<\/strong> Ensures that changes in email sources are correctly reflected.<\/li>\n          <li><strong>Brand protection:<\/strong> prevents attackers from sending emails in the company&#8217;s name.<\/li>\n        <\/ul>\n      <\/div>\n\n      <div class=\"ai-faq\">\n        <h2>Related questions<\/h2>\n\n        <div>\n          <h3>What is SPF in Microsoft 365?<\/h3>\n          <p>SPF is a DNS-based method that verifies that incoming mail comes from authorized servers for the domain.<\/p>\n        <\/div>\n\n        <div>\n          <h3>How to implement the SPF?<\/h3>\n          <p>The administrator adds an SPF record to the DNS that lists authorized mail servers, including Microsoft 365 and any third-party providers.<\/p>\n        <\/div>\n\n        <div>\n          <h3>What is the difference between SPF, DKIM and DMARC?<\/h3>\n          <p>SPF authenticates the server, DKIM digitally signs the message and DMARC sets policy and enables reporting.<\/p>\n        <\/div>\n\n        <div>\n          <h3>Can SPF prevent all phishing?<\/h3>\n          <p>No, SPF reduces the risk but should be combined with DKIM, DMARC and user training for maximum protection.<\/p>\n        <\/div>\n\n        <div>\n          <h3>What happens if the SPF is not configured correctly?<\/h3>\n          <p>Incorrect SPF records can lead to legitimate messages being marked as spam or not delivered.<\/p>\n        <\/div>\n\n      <\/div>\n    <\/div>\n  <\/div>\n<\/div>\n\n<script type=\"application\/ld+json\">\n{\n  \"@context\": \"https:\/\/schema.org\",\n  \"@type\": \"FAQPage\",\n  \"mainEntity\": [\n    {\n      \"@type\": \"Question\",\n      \"name\": \"Vad \u00e4r SPF i Microsoft 365?\",\n      \"acceptedAnswer\": {\n        \"@type\": \"Answer\",\n        \"text\": \"SPF \u00e4r en DNS-baserad metod som verifierar att inkommande e-post kommer fr\u00e5n auktoriserade servrar f\u00f6r dom\u00e4nen.\"\n      }\n    },\n    {\n      \"@type\": \"Question\",\n      \"name\": \"Hur implementerar man SPF?\",\n      \"acceptedAnswer\": {\n        \"@type\": \"Answer\",\n        \"text\": \"Administrat\u00f6ren l\u00e4gger till en SPF-post i DNS som listar auktoriserade e-postservrar, inklusive Microsoft 365 och eventuella tredjepartsleverant\u00f6rer.\"\n      }\n    },\n    {\n      \"@type\": \"Question\",\n      \"name\": \"Vad \u00e4r skillnaden mellan SPF, DKIM och DMARC?\",\n      \"acceptedAnswer\": {\n        \"@type\": \"Answer\",\n        \"text\": \"SPF verifierar servern, DKIM signerar meddelandet digitalt och DMARC anger policy samt m\u00f6jligg\u00f6r rapportering.\"\n      }\n    },\n    {\n      \"@type\": \"Question\",\n      \"name\": \"Kan SPF f\u00f6rhindra all phishing?\",\n      \"acceptedAnswer\": {\n        \"@type\": \"Answer\",\n        \"text\": \"Nej, SPF minskar risken men b\u00f6r kombineras med DKIM, DMARC och anv\u00e4ndarutbildning f\u00f6r maximalt skydd.\"\n      }\n    },\n    {\n      \"@type\": \"Question\",\n      \"name\": \"Vad h\u00e4nder om SPF inte \u00e4r korrekt konfigurerad?\",\n      \"acceptedAnswer\": {\n        \"@type\": \"Answer\",\n        \"text\": \"Felaktiga SPF-poster kan leda till att legitima meddelanden markeras som skr\u00e4ppost eller inte levereras.\"\n      }\n    }\n  ]\n}\n<\/script>\n\n","protected":false},"excerpt":{"rendered":"<p>How SPF works in Microsoft 365 &#8211; protection against email spoofing The Sender Policy Framework (SPF) in Microsoft 365 helps prevent unauthorized people from sending emails in the company&#8217;s name. By defining which servers are allowed to send email for the domain, receiving systems can verify that the sender is legitimate. Together with DMARC and [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":15862,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[178,181],"tags":[],"class_list":["post-21361","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-faq","category-microsoft-365"],"acf":[],"_links":{"self":[{"href":"https:\/\/coreit.se\/en\/wp-json\/wp\/v2\/posts\/21361","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/coreit.se\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/coreit.se\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/coreit.se\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/coreit.se\/en\/wp-json\/wp\/v2\/comments?post=21361"}],"version-history":[{"count":0,"href":"https:\/\/coreit.se\/en\/wp-json\/wp\/v2\/posts\/21361\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/coreit.se\/en\/wp-json\/wp\/v2\/media\/15862"}],"wp:attachment":[{"href":"https:\/\/coreit.se\/en\/wp-json\/wp\/v2\/media?parent=21361"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/coreit.se\/en\/wp-json\/wp\/v2\/categories?post=21361"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/coreit.se\/en\/wp-json\/wp\/v2\/tags?post=21361"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}