Skip to main content

DNS Setup & Domain Readiness

Adding a domain to TenantCore is only the beginning of the setup process. Before a domain is ready for normal outbound use, Microsoft 365 and public DNS need to agree on the records required for mail flow, authentication, and domain verification. TenantCore tracks that progress as domain readiness.

Why DNS records matter

DNS tells Microsoft 365 and receiving mail systems how your domain should send and receive mail, which systems are authorized to send on its behalf, and how authentication failures should be handled. TenantCore focuses on the records required for the Microsoft 365 outbound infrastructure it manages.

The records TenantCore manages

Mail records

MX

The MX record routes mail for your domain to Microsoft 365. TenantCore verifies that the domain points to the expected Microsoft mail infrastructure.

SPF

SPF identifies which systems are authorized to send mail for the domain. For a Microsoft 365-only sending domain, the SPF record normally authorizes Microsoft’s sending infrastructure. Avoid publishing multiple separate SPF TXT records for the same domain. If an SPF record already exists, it may need to be merged rather than duplicated.

DKIM

DKIM signs outbound messages with a cryptographic signature associated with your domain. Microsoft 365 uses two domain-specific CNAME records for DKIM. The normal TenantCore workflow is:
DKIM targets are unique to the domain and tenant. Do not copy DKIM values from another domain.

DMARC

DMARC tells receiving systems how to handle messages that fail domain-alignment checks and provides a policy layer on top of SPF and DKIM. Common policies include:
  • p=none — monitor failures without requesting enforcement
  • p=quarantine — request that failed messages be treated as suspicious
  • p=reject — request that failed messages be rejected
For a dedicated outbound domain with no other legitimate mail sources, p=reject can provide the strongest spoofing protection once SPF and DKIM are configured and verified correctly. Before using it, make sure all legitimate senders for the domain are accounted for.

Microsoft 365 service records

Microsoft can also provide records used for domain verification and other Microsoft 365 services. These can include records for:
  • domain verification
  • Autodiscover
  • device or enterprise enrollment
  • enterprise registration
Not every Microsoft service record affects outbound deliverability directly. TenantCore’s primary concern is ensuring the domain has the records required for the Microsoft 365 and mailbox workflows TenantCore manages.

Automatic DNS

On Plus, Complete, and the 14-day Plus trial, TenantCore can automatically configure supported DNS providers. Current direct-provider support includes:
  • Porkbun
  • Cloudflare
  • Namecheap
The operator connects the DNS provider account to TenantCore. TenantCore then performs supported DNS operations only for domains already registered to the authenticated TenantCore account. The normal flow is:
Some stages take time because DNS propagation and Microsoft-side readiness are external processes. You do not need to keep the browser page open while TenantCore continues setup automatically.

Manual DNS

Automatic DNS is not required. If your DNS provider is unsupported, provider API access is unavailable, or you prefer to make the changes yourself, TenantCore shows the exact records that need to be published. After you add the records at your DNS provider, TenantCore continues checking the domain and updates its readiness state as the records propagate.

Existing DNS records

TenantCore should not blindly replace every record in a DNS zone. The automation workflow plans the Microsoft 365 records required for the domain and applies supported changes through the connected provider. If an existing record conflicts with the required setup or needs operator judgment, TenantCore can surface that condition instead of silently replacing unrelated infrastructure.

Domain readiness

Domain setup is not one synchronous action. The application presents progress in customer-facing states such as:
During setup, TenantCore may be waiting on you, DNS propagation, or Microsoft 365. A Ready domain has completed the required setup checks TenantCore uses for mailbox and DNS workflows. It does not mean the domain is actively sending mail.

Namecheap API eligibility

Namecheap restricts API access to eligible accounts. If your Namecheap account cannot use the API, TenantCore Automatic DNS cannot make direct changes through Namecheap for that account. You can still complete the setup using TenantCore’s manual DNS workflow.

DNS readiness and mailbox creation

Mailbox creation and DNS readiness are related but separate operations. TenantCore can create and manage mailboxes as part of the connected Microsoft 365 tenant workflow while some DNS checks are still progressing. Before sending, wait until the relevant domain authentication and readiness checks are complete.

DNS and the Complete API

The TenantCore API does not accept an arbitrary domain name and act as a generic DNS-provider proxy. Automatic DNS begins from an existing TenantCore domain_id:
The domain must already belong to the authenticated TenantCore account before any provider action is attempted.