> ## Documentation Index
> Fetch the complete documentation index at: https://docs.tenantcore.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Manual DNS Setup

> Configure Microsoft 365 DNS records manually when Automatic DNS is unavailable or not preferred.

# Manual DNS Setup

Manual DNS works with any DNS provider where you can edit the domain's zone.

Use it when:

* the provider is not supported by Automatic DNS
* provider API access is unavailable
* provider eligibility requirements are not met
* you prefer to publish the records yourself

## Open the DNS records

1. Add the domain to the correct TenantCore tenant.
2. Open the domain.
3. Open **DNS records** / the manual setup view.
4. Review the records TenantCore requires.

The exact values are domain-specific. Always copy the current values from TenantCore rather than using sample values from documentation.

## Common record types

TenantCore can require records for:

* Microsoft domain verification
* MX
* SPF
* DMARC
* DKIM

DKIM records may not be available immediately after the first Microsoft setup step.

## Add the records at your DNS provider

For each record:

1. select the correct record type
2. copy the host/name exactly
3. copy the value/target exactly
4. use the provider's normal TTL unless TenantCore specifically requires something different
5. save the record

## Return to TenantCore

After publishing the records, return to the domain and recheck DNS.

DNS changes are not always visible immediately.

TenantCore background checks can continue as the records propagate.

## Do not create duplicate SPF records

A domain should not have multiple separate SPF TXT records.

If the domain already has an SPF record, it may need to be merged rather than adding a second SPF record.

If you are unsure, review the current DNS state before changing it.

## DKIM

DKIM is a two-part process:

1. Microsoft provides the domain-specific DKIM CNAME targets.
2. Those CNAMEs are published in public DNS.

After DNS is visible, TenantCore can enable or verify DKIM through the Microsoft workflow.

## When setup is complete

The domain should show the expected MX/SPF/DMARC/DKIM health and Microsoft verification state.

Do not assume a domain is ready simply because the records were saved at the DNS provider.
