Microsoft, Microsoft 365, Outlook, SharePoint, OneDrive, Microsoft Teams, Microsoft Graph, Azure, and Entra are trademarks of the Microsoft group of companies. ImpressionsDirect360 is an independent provider and is not affiliated with, sponsored by, or endorsed by Microsoft.
Mail you send is being filtered by the people you send it to. That is almost always authentication: the three DNS records that prove a message really came from your domain.
Microsoft 365 is usually only one of them. Your CRM, invoicing tool, booking system, and marketing platform may all send as you, and each one has to be authorised.
We read your live SPF, DKIM, and DMARC records and compare them against that list, including the classic faults: two SPF records where there should be one, or more than ten DNS lookups in the chain.
One SPF record covering every legitimate sender, DKIM signing enabled and selectors published for your domain, and a DMARC record that starts in monitoring mode so nothing legitimate is dropped while we watch.
Monitoring mode collects reports on what is passing and failing. Only once the legitimate senders are clean do we move the policy to quarantine, then reject.
We send test mail to external mailboxes and read the received headers to confirm all three checks pass, rather than trusting an internal send.
Three DNS records that together prove a message really came from your domain. SPF lists the servers allowed to send as you, DKIM adds a cryptographic signature to every message, and DMARC tells receiving mail systems what to do when a message fails those checks and where to send reports.
Usually because something changed on the sending side: a new marketing or invoicing tool started sending as your domain without being added to SPF, a DNS record was edited, or a receiving provider tightened its enforcement of DMARC. The message content is rarely the cause.
Yes. We tell you exactly which records to change, or make the changes for you if you would rather give us access to the DNS zone. The records live wherever your domain is hosted — they do not have to be at Microsoft.
DNS changes propagate in minutes to a few hours. Sender reputation recovers more slowly — expect days rather than minutes for a domain that has been failing checks for a long time.
As soon as it costs you a reply. Deliverability compounds — the longer a domain sends unauthenticated mail, the worse its reputation gets — so raise it early rather than waiting for it to settle.
If the fault turns out to be in the Microsoft service rather than your setup, we take it from there — you keep one point of contact.