Exchange online SPF

%3CLINGO-SUB%20id%3D%22lingo-sub-1108328%22%20slang%3D%22en-US%22%3EExchange%20online%20SPF%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1108328%22%20slang%3D%22en-US%22%3E%3CP%3EI%20may%20be%20missing%20something%20basic%20here%20but%20can%20someone%20explain%20if%20I%20used%20the%20recommended%20spf%20include%20statement%20(%3CSPAN%3Ev%3Dspf1%20include%3Aspf.protection.outlook.com%20-all(%20(see%20here%3A%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fmicrosoft-365%2Fsecurity%2Foffice-365-security%2Fset-up-spf-in-office-365-to-help-prevent-spoofing%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fmicrosoft-365%2Fsecurity%2Foffice-365-security%2Fset-up-spf-in-office-365-to-help-prevent-spoofing%3C%2FA%3E)%20for%20all%20exchange%20online%20deployment%20because%26nbsp%3Bits%20not%20specific%26nbsp%3Bto%20my%20domain%20rather%20generic%20to%20outlook.com%20wouldn't%26nbsp%3Bthat%20mean%20that%20any%20other%20exchange%20online%20customer%20could%20spoof%20my%20domain%3F%26nbsp%3B%20If%20they%20are%20also%20coming%20from%20that%20host%20being%20a%20exchange%20online%20user%20just%20like%20me%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%3EDoes%20that%20make%20sense%3F%26nbsp%3B%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-1108328%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EExchange%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E
Contributor

I may be missing something basic here but can someone explain if I used the recommended spf include statement (v=spf1 include:spf.protection.outlook.com -all( (see here: https://docs.microsoft.com/en-us/microsoft-365/security/office-365-security/set-up-spf-in-office-365...) for all exchange online deployment because its not specific to my domain rather generic to outlook.com wouldn't that mean that any other exchange online customer could spoof my domain?  If they are also coming from that host being a exchange online user just like me

 

Does that make sense? 

 

1 Reply

Only if you are sending via the ExO IP ranges, the ones listed when you expand spf.protection.outlook.com. Which Microsoft will only allow you to do for your own domain(s).