Setting Up Office 365 Email On Outlook

The user has office 365 business premium, we've never had an issue before with this. For some reason when opening outlook and entering his email, it just searches for a while then comes back saying 'Something went wrong and Outlook couldn’t set up your account. Please try again. If the problem continues, contact your email administrator.'

  • Outlook 2016 for MacOS. To set up Outlook 2016 for MacOS, Open Outlook. Navigate to Tools. Select Accounts. Click Add Email Account. Alternatively, you can click the + at the bottom left of the window. Enter your UConn Office 365 faculty, staff or student worker email address. Enter your NetID password.
  • To set up an Office 365/Outlook/Exchange account, make sure that email account settings are correct (server/hostname, port, SSL, and password). You can find this information in your email client app settings or you can ask your IT specialist. For example, in Outlook - Sync mail tab as shown on the screenshot below.
  • Configure Outlook. You can configure Microsoft Outlook to access your Office 365 account by setting up an Exchange connection. An Exchange connection provides access your email, calendar, contacts, and tasks in Outlook. Note: Two-step authentication may also be required. On the Outlook menu, click Preferences and then click.
  • You can configure Microsoft Outlook to access your Office 365 account by setting up an Exchange connection. An Exchange connection provides access your email, calendar, contacts, and tasks in Outlook. You can also set up Outlook to access your email by using IMAP.
-->

This article describes how to update a Domain Name Service (DNS) record so that you can use Sender Policy Framework (SPF) email authentication with your custom domain in Office 365.

SPF helps validate outbound email sent from your custom domain (is coming from who it says it is). It's a first step in setting up the full recommended email authentication methods of SPF, DKIM, and DMARC.

  • Create or update your SPF TXT record
  • What does SPF email authentication actually do?

Prerequisites

Important

If you are a small business, or are unfamiliar with IP addresses or DNS configuration, call your Internet domain registrar (ex. GoDaddy, Bluehost, web.com) & ask for help with DNS configuration of SPF (and any other email authentication method).

If you don't use a custom URL (and the URL used for Office 365 ends in onmicrosoft.com), SPF has already been set up for you in the Office 365 service.

Let's get started.

The SPF TXT record for Office 365 will be made in external DNS for any custom domains or subdomains. You need some information to make the record. Gather this information:

  • The SPF TXT record for your custom domain, if one exists. For instructions, see Gather the information you need to create Office 365 DNS records.

  • Go to your messaging server(s) and find out the External IP addresses (needed from all on-premises messaging servers). For example, 131.107.2.200.

  • Domain names to use for all third-party domains that you need to include in your SPF TXT record. Some bulk mail providers have set up subdomains to use for their customers. For example, the company MailChimp has set up servers.mcsv.net.

  • Figure out what enforcement rule you want to use for your SPF TXT record. The -all rule is recommended. For detailed information about other syntax options, see SPF TXT record syntax for Office 365.

Important

In order to use a custom domain, Office 365 requires that you add a Sender Policy Framework (SPF) TXT record to your DNS record to help prevent spoofing.

Create or update your SPF TXT record

  1. Ensure that you're familiar with the SPF syntax in the following table.
ElementIf you're using...Common for customers?Add this...
1Any email system (required)Common. All SPF TXT records start with this valuev=spf1
2Exchange OnlineCommoninclude:spf.protection.outlook.com
3Exchange Online dedicated onlyNot commonip4:23.103.224.0/19
ip4:206.191.224.0/19
ip4:40.103.0.0/16
include:spf.protection.outlook.com
4Office 365 Germany, Microsoft Cloud Germany onlyNot commoninclude:spf.protection.outlook.de
5Third-party email systemNot commoninclude:<domain_name>

<domain_name> is the domain of the third-party email system.

6On-premises email system. For example, Exchange Online Protection plus another email systemNot commonUse one of these for each additional mail system:

ip4:<IP_address>
ip6:<IP_address>
include:<domain_name>

<IP_address> and <domain_name> are the IP address and domain of the other email system that sends mail on behalf of your domain.

7Any email system (required)Common. All SPF TXT records end with this value<enforcement rule>

This can be one of several values. We recommend the value -all.

  1. If you haven't already done so, form your SPF TXT record by using the syntax from the table.

    For example, if you are hosted entirely in Office 365, that is, you have no on-premises mail servers, your SPF TXT record would include rows 1, 2, and 7 and would look like this:

    The example above is the most common SPF TXT record. This record works for just about everyone, regardless of whether your Microsoft datacenter is located in the United States, or in Europe (including Germany), or in another location.

    However, if you bought Office 365 Germany, part of Microsoft Cloud Germany, you should use the include statement from line 4 instead of line 2. For example, if you are hosted entirely in Office 365 Germany, that is, you have no on-premises mail servers, your SPF TXT record would include rows 1, 4, and 7 and would look like this:

    If you're already deployed in Office 365 and have set up your SPF TXT records for your custom domain, and you're migrating to Office 365 Germany, you need to update your SPF TXT record. To do this, change include:spf.protection.outlook.com to include:spf.protection.outlook.de.

  2. Once you have formed your SPF TXT record, you need to update the record in DNS. You can only have one SPF TXT record for a domain. If an SPF TXT record exists, instead of adding a new record, you need to update the existing record. Go to Create DNS records for Office 365, and then select the link for your DNS host.

  3. Test your SPF TXT record.

How to handle subdomains?

It's important to note that you need to create a separate record for each subdomain as subdomains don't inherit the SPF record of their top-level domain.

A wildcard SPF record (*.) is required for every domain and subdomain to prevent attackers from sending email claiming to be from non-existent subdomains. For example:

Troubleshooting SPF

Having trouble with your SPF TXT record? Read Troubleshooting: Best practices for SPF in Office 365.

What does SPF email authentication actually do?

SPF identifies which mail servers are allowed to send mail on your behalf. Basically, SPF, along with DKIM, DMARC, and other technologies supported by Office 365, help prevent spoofing and phishing. SPF is added as a TXT record that is used by DNS to identify which mail servers can send mail on behalf of your custom domain. Recipient mail systems refer to the SPF TXT record to determine whether a message from your custom domain comes from an authorized messaging server.

For example, let's say that your custom domain contoso.com uses Office 365. You add an SPF TXT record that lists the Office 365 messaging servers as legitimate mail servers for your domain. When the receiving messaging server gets a message from joe@contoso.com, the server looks up the SPF TXT record for contoso.com and finds out whether the message is valid. If the receiving server finds out that the message comes from a server other than the Office 365 messaging servers listed in the SPF record, the receiving mail server can choose to reject the message as spam.

Also, if your custom domain does not have an SPF TXT record, some receiving servers may reject the message outright. This is because the receiving server cannot validate that the message comes from an authorized messaging server.

If you've already set up mail for Office 365, then you have already included Microsoft's messaging servers in DNS as an SPF TXT record. However, there are some cases where you may need to update your SPF TXT record in DNS. For example:

  • Previously, you had to add a different SPF TXT record to your custom domain if you were using SharePoint Online. This is no longer required. This change should reduce the risk of SharePoint Online notification messages ending up in the Junk Email folder. Update your SPF TXT record if you are hitting the 10 lookup limit and receiving errors that say things like, 'exceeded the lookup limit' and 'too many hops'.

  • If you have a hybrid environment with Office 365 and Exchange on-premises.

  • You intend to set up DKIM and DMARC (recommended).

More information about SPF

For advanced examples, a more detailed discussion about supported SPF syntax, spoofing, troubleshooting, and how Office 365 supports SPF, see How SPF works to prevent spoofing and phishing in Office 365.

Next Steps: DKIM and DMARC

SPF is designed to help prevent spoofing, but there are spoofing techniques that SPF can't protect against. To defend against these, once you've set up SPF, you should configure DKIM and DMARC for Office 365.

DKIM email authentication's goal is to prove the contents of the mail haven't been tampered with.

DMARC email authentication's goal is to make sure that SPF and DKIM information matches the From address.

For advanced examples and a more detailed discussion about supported SPF syntax, see How SPF works to prevent spoofing and phishing in Office 365.

Select 'This page' under 'Feedback' if you have feedback on this documentation.

-->

Original KB number: 4493666

Symptoms

You can't successfully set up an Office 365 Exchange Online email account in Outlook.

Cause

This issue might occur if your Exchange administrator enables multi-factor authentication (MFA) for your account, but doesn't enable modern authentication for the Exchange tenant organization.

When this issue occurs, the server returns an HTTP 456 authentication error.

Resolution

To fix this issue, disable MFA for the account in the Office 365 admin center. To do this, follow these steps.

Note

You might have to contact your Exchange administrator to disable the MFA .

Setting Up Office 365 Email On Outlook
  1. Browse to the Office 365 portal, and sign in to your Office 365 subscription by using your Global Administrator account.
  2. On the main portal page, select Admin.
  3. In the navigation pane, select Users > Active users.
  4. In the Active users pane, select More > Multi-factor authentication setup.
  5. Select the check box next to the affected user.
  6. Under quick steps, select Disable.

More information

Setting Up Office 365 Email On Outlook For Mac

To enable MFA for organizations, Exchange administrators must enable modern authentication in Exchange Online. By default, newer Exchange Online tenants have modern authentication enabled.

You can enable modern authentication for tenants as necessary. Before you enable modern authentication for your Exchange organization, take compatibilities into account. Consider that the user experience will change if MFA is enabled in your organization.

Setting Up Office 365 Email On Iphone Using Outlook App

For more information, see the following websites: