Two weeks out from the October filing deadline, the worst email problem a CPA firm can have isn't a full inbox. It's a client who never got your message — or got one that wasn't from you.
Here's the part that surprises most firm owners: Microsoft 365 doesn't set this up for you. When you added your domain, Microsoft didn't publish a DMARC record on your behalf. That record lives at your DNS host, and somebody has to go put it there. And unless someone turned on DKIM signing for your actual domain, your outbound mail may still be signed with the onmicrosoft.com name you were handed at setup.
Think of SPF, DKIM and DMARC as the letterhead, the signature, and the standing instructions to the mailroom. Without all three, a receiving mail system has no dependable way to tell your email from someone impersonating your firm. That's how a client ends up wiring an estimated payment to an account nobody at your office ever typed.
Microsoft's own guidance is to walk it in stages: publish the record in monitor mode, watch what it reports for a few weeks, then tighten it until impersonated mail gets rejected outright.
No new software, no new license. It's DNS. Worth a look before the next busy season — and before your next cyber renewal.
Want the next one in your inbox?
One practical Microsoft 365, Copilot, Azure, or security move per week — plain English, no pitch.
Subscribe via email