DNS Setup & Domain Readiness
Adding a domain to TenantCore is only the beginning of the setup process. Before a domain is ready for normal outbound use, Microsoft 365 and public DNS need to agree on the records required for mail flow, authentication, and domain verification. TenantCore tracks that progress as domain readiness.Why DNS records matter
DNS tells Microsoft 365 and receiving mail systems how your domain should send and receive mail, which systems are authorized to send on its behalf, and how authentication failures should be handled. TenantCore focuses on the records required for the Microsoft 365 outbound infrastructure it manages.The records TenantCore manages
Mail records
MX
The MX record routes mail for your domain to Microsoft 365. TenantCore verifies that the domain points to the expected Microsoft mail infrastructure.SPF
SPF identifies which systems are authorized to send mail for the domain. For a Microsoft 365-only sending domain, the SPF record normally authorizes Microsoft’s sending infrastructure. Avoid publishing multiple separate SPF TXT records for the same domain. If an SPF record already exists, it may need to be merged rather than duplicated.DKIM
DKIM signs outbound messages with a cryptographic signature associated with your domain. Microsoft 365 uses two domain-specific CNAME records for DKIM. The normal TenantCore workflow is:DMARC
DMARC tells receiving systems how to handle messages that fail domain-alignment checks and provides a policy layer on top of SPF and DKIM. Common policies include:p=none— monitor failures without requesting enforcementp=quarantine— request that failed messages be treated as suspiciousp=reject— request that failed messages be rejected
For a dedicated outbound domain with no other legitimate mail sources,
p=reject can provide the strongest spoofing protection once SPF and DKIM are configured and verified correctly. Before using it, make sure all legitimate senders for the domain are accounted for.Microsoft 365 service records
Microsoft can also provide records used for domain verification and other Microsoft 365 services. These can include records for:- domain verification
- Autodiscover
- device or enterprise enrollment
- enterprise registration
Automatic DNS
On Plus, Complete, and the 14-day Plus trial, TenantCore can automatically configure supported DNS providers. Current direct-provider support includes:- Porkbun
- Cloudflare
- Namecheap
Manual DNS
Automatic DNS is not required. If your DNS provider is unsupported, provider API access is unavailable, or you prefer to make the changes yourself, TenantCore shows the exact records that need to be published. After you add the records at your DNS provider, TenantCore continues checking the domain and updates its readiness state as the records propagate.Existing DNS records
TenantCore should not blindly replace every record in a DNS zone. The automation workflow plans the Microsoft 365 records required for the domain and applies supported changes through the connected provider. If an existing record conflicts with the required setup or needs operator judgment, TenantCore can surface that condition instead of silently replacing unrelated infrastructure.Domain readiness
Domain setup is not one synchronous action. The application presents progress in customer-facing states such as:Namecheap API eligibility
Namecheap restricts API access to eligible accounts. If your Namecheap account cannot use the API, TenantCore Automatic DNS cannot make direct changes through Namecheap for that account. You can still complete the setup using TenantCore’s manual DNS workflow.DNS readiness and mailbox creation
Mailbox creation and DNS readiness are related but separate operations. TenantCore can create and manage mailboxes as part of the connected Microsoft 365 tenant workflow while some DNS checks are still progressing. Before sending, wait until the relevant domain authentication and readiness checks are complete.DNS and the Complete API
The TenantCore API does not accept an arbitrary domain name and act as a generic DNS-provider proxy. Automatic DNS begins from an existing TenantCoredomain_id: