Outlook / Exchange Online SPF record

Business Outlook (Exchange Online, part of Microsoft 365) uses the same single-lookup include as Microsoft 365: spf.protection.outlook.com. Consumer Outlook.com mailboxes are sent on Microsoft’s behalf and do not need an include in your domain’s record.

The SPF include for Outlook / Exchange Online

Authorize Outlook / Exchange Online by adding its mechanism to your single SPF TXT record:

v=spf1 include:spf.protection.outlook.com ~all

Approximate lookup cost: 1 DNS lookup(s). Remember you have a budget of 10 total across every sender in the record.

Provider include values change occasionally. Confirm the current value in your Outlook / Exchange Online admin console before publishing, and never create a second v=spf1 record — a domain may have only one. Combine all senders into one record:

v=spf1 include:spf.protection.outlook.com include:spf.protection.outlook.com ~all

If you already have the Microsoft 365 include, you do not add it twice for Outlook — they are the same platform. Duplicate includes are a common cause of wasted lookups.

When adding Outlook / Exchange Online pushes you over the limit

Every include you stack — your mailbox provider, this one, a marketing tool, a help desk — adds to the same 10-lookup budget. The moment recursive expansion crosses 10, receivers return permerror and your SPF stops passing. You cannot shrink the nested provider records, so the durable fix is to flatten the record or move to a single-lookup macro that stays in sync automatically.

Frequently asked questions

What is the SPF include for Outlook / Exchange Online?
Add include:spf.protection.outlook.com to your single SPF record, e.g. v=spf1 include:spf.protection.outlook.com ~all. Verify the current value in your Outlook / Exchange Online admin console.
How many DNS lookups does it use?
About 1 lookup(s) — out of the maximum of 10 allowed across your whole SPF record.
Can I have a separate SPF record just for this provider?
No. A domain may publish only one SPF (TXT starting v=spf1) record. Publishing two causes a permerror. Merge every sender into a single record.

Test your SPF record now

Adding Outlook / Exchange Online to a record that already has other senders? Check how many DNS lookups you are using and whether you have crossed the limit.

Test My SPF Records →

Free check · no signup required to see your lookup count.