• Blog
  • DNS toolbox
  • French
  • Offers
  • Linkedin
  • FAQ
  • …  
    • Blog
    • DNS toolbox
    • French
    • Offers
    • Linkedin
    • FAQ
broken image
broken image
broken image

 

  • Blog
  • DNS toolbox
  • French
  • Offers
  • Linkedin
  • FAQ
  • …  
    • Blog
    • DNS toolbox
    • French
    • Offers
    • Linkedin
    • FAQ
    Request a Free Trial
    • Blog
    • DNS toolbox
    • French
    • Offers
    • Linkedin
    • FAQ
    • …  
      • Blog
      • DNS toolbox
      • French
      • Offers
      • Linkedin
      • FAQ
    broken image
    broken image
    broken image

     

    • Blog
    • DNS toolbox
    • French
    • Offers
    • Linkedin
    • FAQ
    • …  
      • Blog
      • DNS toolbox
      • French
      • Offers
      • Linkedin
      • FAQ
      Request a Free Trial
      broken image

      Protect your onmicrosoft.com domain with DMARC

      · M365
      French version

      When you set up your M365 tenant, Microsoft automatically reserved a domain for you—something you might have forgotten if it’s been a while :

      • xxxx.onmicrosoft.com (MOERA - Microsoft Online Email Routing Address).

      For instance at Oppidum Security : oppidumsecurity.onmicrosoft.com

      Your users can therefore receive e-mails on their addresses:

      broken image

      However, you probably don't use this domain to send email. Nevertheless, just like your defensive domains, you can protect it with DMARC by setting up a DMARC record:

      1. Open the Microsoft 365 admin center at https://admin.microsoft.com.
      2. On the left-hand navigation, select Show All.
      3. Expand Settings and press Domains.
      4. Select your tenant domain (for example, contoso.onmicrosoft.com).
      5. On the page that loads, select DNS records.
      6. Select + Add record.
      7. A flyout will appear on the right. Ensure that the selected Type is TXT (Text).
      8. Add _dmarc as TXT name.
      9. Add your specific DMARC value.
      10. Press Save.

      For example, to monitor and protect our domain oppidumsecurity.onmicrosoft.com against spoofing of its email addresses, below is the DMARC record we have configured :

      broken image

      After the DMARC policy has been set to restrictive mode, an email spoofing a xx@oppidumsecurity.com address is automatically sent to the spam folder of our collaborators (other actions are possible like rejecting the email)

      broken image
      broken image
      How to protect parked domains using SPF, DKIM and DMARC?​

      Previous
      How to protect parked domains using SPF, DKIM and DMARC ?
      Next
      Malicious IPs and Domains Take down
       Return to site
      Profile picture
      Cancel
      Cookie Use
      We use cookies to improve browsing experience, security, and data collection. By accepting, you agree to the use of cookies for advertising and analytics. You can change your cookie settings at any time. Learn More
      Accept all
      Settings
      Decline All
      Cookie Settings
      Necessary Cookies
      These cookies enable core functionality such as security, network management, and accessibility. These cookies can’t be switched off.
      Analytics Cookies
      These cookies help us better understand how visitors interact with our website and help us discover errors.
      Preferences Cookies
      These cookies allow the website to remember choices you've made to provide enhanced functionality and personalization.
      Save