SPF(supported) (dedicated subdomain)
DKIM(recommended)



This article covers the SPF and DKIM authentication processes for Microsoft Dynamics 365 and how they are managed in Valimail Enforce. While only one of the two authentication methods is required for an email to pass DMARC, our recommendation is to configure both whenever possible.

Microsoft Dynamics 365 does not send SPF aligned emails by default.




TABLE OF CONTENTS




Configuring DKIM authentication for your Microsoft Dynamics 365 emails


1. Go to Settings -> Email marketing -> Domain authentication. A list of existing authenticated domains opens.


a screenshot of a search box


2. Select New on the command bar to add a new domain. The wizard will guide you through the whole domain authentication process step by step. On the first step you will need to enter the domain name that you want to authenticate and select if it will be used for forms hosting and email sending capabilities.


a screenshot of a computer


3. On the next step you will be asked to add your first DNS record, which will check and confirm the ownership of your domain. Use “Copy” buttons to accurately copy the values of TXT record to avoid typos.


a screenshot of a computer


4. The next 2 steps will guide you through the setup process of CNAME records (CNAME1 and CNAME2) that stand for DKIM protection functionality. These 2 DKIM CNAME records must be published on your domain's Configuration page in Valimail Enforce.


a screenshot of a computer


a screenshot of a computer


5. The next step stands for the last required CNAME DNS record, which is for Envelope-From (Return-Path) domain alignment and SPF protection functionality. This last CNAME record needs to be added in your DNS.


a screenshot of a computer


6. On the last step you will be able to review and check your published DNS records. After your checkup is finished, select Verify. The system will check and validate all published DNS records and will show you the result summary on the dashboard. If there’s something wrong with your DNS records, you will see which exact record fails on the dashboard.


Here’s an example of an error message that states that TXT Ownership key was not found published in the DNS, which means either the record was not yet published, or it has some mistake/typo.


a screenshot of a computer screen



You can also find the instructions on how to set up DKIM and SPF for Microsoft Dynamics 365, here.





Add a Microsoft Dynamics 365 DKIM key in Enforce


1. Go to your domain's Configuration page in Valimail Enforce and publish the newly created DKIM key.


    a. Scroll down and add the two DKIM keys in your configuration, by clicking on Add a DKIM key

    b. Enter the selector name, CNAME target value, associate the key/s with Microsoft Dynamics 365 and then click Add.


a screenshot of a computer


You can find more detailed information on how to add a DKIM key in Valimail Enforce here. 





Configuring SPF authentication for your Microsoft Dynamics 365 emails


Once you establish that Microsoft Dynamics 365 is an authorized sender for your domain, you will need to add the service in your Enabled Senders list in Enforce.


1. Please go to your domain's Configuration page in Enforce.

2. Click on the + sign from the Enabled Senders section:


a screenshot of a email


3. Choose Microsoft Dynamics 365 from the list of configurable senders and then click Enable:


a screenshot of a computer


We encourage you to use the comment section for any useful information about your sending service, such as the name of the service owner, change request ticket numbers, etc.







As always, if you have any questions, please don't hesitate to submit a ticket.