Before you start
You need a Global Administrator account in your GCC High tenant.
You need access to your domain's DNS settings at your registrar, such as GoDaddy, Cloudflare, or Namecheap.
Use a private or incognito browser window. This keeps you from signing into the wrong Microsoft cloud by mistake.
Step 1: Add your domain in Microsoft Entra
Open entra.microsoft.us and sign into the Microsoft Entra admin center.
Open the custom domain names. You can also find it under Entra ID > Domain names.
Click "+ Add custom domain", enter your chosen domain, and click Add domain.
Entra will show a verification record for your new record. Leave the record type set to TXT.
Leave this page open for later.
If "+ Add custom domain" is missing or grayed out, your account doesn't have the right role. Find a different account that has the Global Administrator role.
Step 2: Add the verification record at your registrar
Open the DNS settings for your domain at your registrar.
Add a new TXT record with the name
@and the value from Entra ID. Copy the value exactly, with no quotes or extra spaces.Save the record.
If you already have other TXT records, keep them. Add this one as a separate record.
Step 3: Verify the domain
Wait 5 to 15 minutes.
Go back to Entra and click Verify.
When it works, your domain shows as Verified in the Domain names list.
Here is an example of what a verified domain looks like:
Optional: make it your primary domain. In Domain names, click your domain, then Make primary. New users will get an address on your domain by default. Existing users keep their current usernames.
Step 4: Check your tenant name (Secureframe virtual desktops only)
Skip this step if you are not using Secureframe virtual desktops.
Your tenant prefix is the part before .onmicrosoft.us. You can see it in the Microsoft 365 admin center under Settings > Domains.
Example tenant | Prefix length | What to do |
| 4 | Skip this step |
| 16 | Add an |
Secureframe virtual desktops use Microsoft Entra Domain Services which only accepts tenant names with 15 characters or fewer. If your tenant name is longer than that, you will need to create a new tenant domain name that is 15 characters or less.
How to add a shorter domain:
In Entra, go to Domain names, click + Add custom domain, and enter
adsf.followed by your domain. For example,adsf.acmemanufacturer.com. Useadsfexactly. Other names, such asmail., won't work.Entra usually verifies it right away because your main domain is already verified. If it asks for a TXT record, add it at your registrar with the name
adsf(not@) and the new value. Then click Verify.Take a screenshot of the Domain names list showing both domains as Verified. Send it to your Secureframe contact. We need it to set up your virtual desktops.
Step 5: Add the email records
Does this domain already have email with another provider? Contact us before you change its MX or SPF records. Changing them moves your email to Microsoft.
In the Microsoft 365 admin center, go to Settings > Domains and select your domain. Microsoft shows the exact records for your tenant.
If Microsoft offers to add the records for you, sign in to your registrar when it asks. This is the fastest option. Otherwise, add the records yourself at your registrar. Use the values Microsoft shows you. They look like the table below.
Delete any placeholder MX records your registrar added. Keep only Microsoft's MX record.
If you have a CNAME record named
msoid, delete it. It stops Microsoft 365 apps from activating.If Microsoft lists more records than the table, add those too.
In the admin center, click Check DNS. Each record turns green when Microsoft finds it. If one stays red after 30 minutes, the message tells you which value doesn't match.
Type | Name | Value | Needed? |
MX |
| Copy from the admin center. It ends in | Yes |
TXT (SPF) |
|
| Yes. See step 6. |
CNAME |
|
| Yes |
SRV |
|
| Only if you use Teams with outside organizations |
Use a TTL of 1 hour for every record. Every value ends in .us.
Step 6: Check your SPF record
SPF tells other mail servers which servers can send email for your domain.
Your domain can only have one SPF record, which is a TXT record that starts with v=spf1. If it has two, mail servers ignore both and your email is more likely to be rejected.
If another service already has an SPF record on your domain, don't add a second one. Add include:spf.protection.office365.us to the record you have. For example:
v=spf1 include:spf.protection.office365.us include:your-other-service.com -all
Step 7: Turn on DKIM
DKIM adds a signature to your outgoing email that proves it came from your domain. Without it, email to Gmail and Yahoo is more likely to go to spam. Turn it on as soon as your email records are in place.
Open the DKIM page in the Exchange admin center.
Select your domain. Exchange shows two CNAME records, one named
selector1._domainkeyand one namedselector2._domainkey.Add both records at your registrar. Copy the names and values exactly as Exchange shows them.
Wait 5 to 10 minutes.
In Exchange, turn on Sign messages for this domain with DKIM signatures.
If Exchange says it can't find the records, wait a few more minutes and try again.
Step 8: Add DMARC (recommended)
DMARC tells mail servers what to do with email that fails SPF or DKIM, and sends you reports about it.
Type | Name | Value |
TXT |
|
|
With p=none, nothing gets blocked. You only get reports. The address after mailto: must be a real mailbox or a forwarding address.
Once the reports show your real email passing, change p=none to p=quarantine. Failing email then goes to spam. Later, change it to p=reject, and failing email is refused.
Step 9: Test your email
Give a user a mailbox. Their username must end in your domain, and they need a license that includes Exchange Online. The mailbox is ready in 5 to 15 minutes.
From an outside account, such as Gmail, send an email to that user. Check that it arrives in Outlook on the web.
Reply to the Gmail account.
In Gmail, open the reply, click the three-dot menu, and choose Show original.
Check that SPF, DKIM, and DMARC all show PASS.
If a check fails, look for these common causes:
A DNS value ends in
.cominstead of.us.The domain has two SPF records.
DKIM isn't turned on yet. DKIM shows NEUTRAL until it is.
The user has no Exchange Online license, so they have no mailbox.
DNS changes haven't spread yet. Wait 30 minutes and test again.
Step 10: Backup emergency admin account (break-glass)
If your domain's DNS breaks, or the domain is removed from your tenant, no one with a username on that domain can sign in. Microsoft recommends keeping emergency access accounts for this.
This break-glass account is already created as part of the GCC High navigator, but in case you don't go through that workflow, here are the requirements:
Create one or two Global Administrator accounts on your
.onmicrosoft.usdomain. Store their login credentials somewhere safe.These accounts don't need a license.
Sign-in once to confirm they work.
GCC High URLs:
Site | Address |
Microsoft 365 admin center | |
Microsoft Entra admin center | |
Exchange admin center | |
Azure Government portal | |
Outlook on the web |
Questions? Message your Secureframe team from the chat in the app.


