Prepare each custom domain
- Configure SPF for active custom sending domains.
- Enable DKIM signing using the custom domain.
- Publish DMARC in public DNS for the custom domain.
- Treat unused domains separately with a reject policy when appropriate.
Separate bulk and application mail
Microsoft recommends using subdomains for services not under your direct control so authentication or reputation problems do not affect the primary user-mail domain. Those services still need aligned authentication.
Interpret reporting
Microsoft 365 traffic spans broad infrastructure. Look for an aligned custom-domain DKIM signature and expected Mail From behaviour. Do not authorise a source based only on an IP that once appeared in a Microsoft range.
Further readingMicrosoft 365 DMARC configuration