Connect Microsoft 365
The correct setup depends on where your Microsoft 365 subscription was purchased.
Purchased through SaaSTech
Your required Microsoft 365 DNS is configured automatically by the SaaSTech system.
What you should do
- 1
Confirm your subscription is active in your SaaSTech account.
- 2
Allow the automated setup to complete.
- 3
Contact SaaSTech support if Microsoft reports a missing record.
Purchased from Microsoft or elsewhere
Continue below. Microsoft will show tenant-specific verification and mail records that you must add in your domain DNS.
Manual connection steps
Open your domain’s DNS
- Sign in to your SaaSTech Servers Domain Portfolio External · opens new tab ↗.
- Select the individual domain to open its Domain Settings page.
- Select DNS.
Need help signing in? Find your username or password External · opens new tab ↗.
Add the domain in Microsoft 365
Sign in at admin.microsoft.com, then go to Settings → Domains → Add domain. Enter the domain and choose the manual setup path if you are adding records yourself.Open Microsoft 365 AdminExternal · opens new tab ↗Microsoft: add a domainExternal · opens new tab ↗
Verify ownership with TXT
Copy the unique MS=msXXXXXXXX TXT value shown by Microsoft in your domain DNS, then return to Microsoft and select Verify. Use the exact value from your tenant.Add a TXT record in SaaSTech DNSExternal · opens new tab ↗Microsoft: find your DNS recordsExternal · opens new tab ↗
Prepare users and mailboxes
Create every user, shared mailbox, alias, and group before the MX change. Microsoft recommends completing mailbox preparation before redirecting incoming email.
Copy Microsoft’s required records
In Settings → Domains, select the domain and continue setup. Copy the MX, Autodiscover, SPF, and any additional records Microsoft lists for the services you selected.Open Microsoft 365 AdminExternal · opens new tab ↗Manage records in SaaSTech DNSExternal · opens new tab ↗
Make the mail cutover
At the approved time, add the reviewed records. The tenant-specific MX target ends in mail.protection.outlook.com. Remove old MX records only when mail should start flowing to Microsoft 365.Add an MX record in SaaSTech DNSExternal · opens new tab ↗DNS Cutover GuideSaaSTech guide →
Verify and authenticate
Finish domain setup, test external mail in both directions, then configure DKIM and DMARC. Monitor through the old TTL period and use the rollback plan if a critical check fails.Check mail records with MXToolboxExternal · opens new tab ↗
Typical Microsoft 365 records
| Purpose | Type | Host | Value |
|---|---|---|---|
| Verify domain | TXT | @ | MS=msXXXXXXXX |
| Receive mail | MX | @ | Your tenant’s *.mail.protection.outlook.com target |
| Outlook setup | CNAME | autodiscover | autodiscover.outlook.com |
| Authorize sending | TXT | @ | Microsoft 365 SPF value, merged with other senders |
The verification and MX values above are patterns, not values to copy. Use exactly what your Microsoft 365 admin centre displays. Additional Microsoft services can require more records.
