<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
</head>
<body dir="auto">
From the Microsoft 365 Message Center dated April 4th 2025:
<div><br>
</div>
<div>\u201c<span style="-webkit-text-size-adjust: auto; caret-color: rgb(179, 179, 179); color: rgb(179, 179, 179); font-family: "Segoe UI", "Segoe UI Web (West European)", "Segoe UI", -apple-system, BlinkMacSystemFont, Roboto, "Helvetica Neue", sans-serif; font-size: 14px; background-color: rgb(33, 33, 33);"> We\u2019re
making some changes to DNS provisioning of A records for all new Accepted Domains provisioned after July 1st, 2025. Between July 1st and August 1st, 2025, we will gradually switch provisioning of all A records for new Accepted Domains into the new subdomains
under mx.microsoft.We are doing this to reduce the friction of adopting DNSSEC in the long run. DNSSEC is a set of extensions to DNS that provides cryptographic verification of DNS records, preventing DNS spoofing and adversary-in-the-middle attacks to DNS. </span><b style="-webkit-text-size-adjust: auto; box-sizing: inherit; color: rgb(237, 237, 237); font-family: "Segoe UI", "Segoe UI Web (West European)", "Segoe UI", -apple-system, BlinkMacSystemFont, Roboto, "Helvetica Neue", sans-serif; font-size: 14px;">How
this will affect your organization:</b><span style="-webkit-text-size-adjust: auto; caret-color: rgb(179, 179, 179); color: rgb(179, 179, 179); font-family: "Segoe UI", "Segoe UI Web (West European)", "Segoe UI", -apple-system, BlinkMacSystemFont, Roboto, "Helvetica Neue", sans-serif; font-size: 14px; background-color: rgb(33, 33, 33);"> After
August 1st 2025, all A records for new Accepted Domains will be provisioned into the new subdomains under mx.microsoft. DNS resolution will safely fallback to \u201cplain\u201d DNS if a domain is not DNSSEC enabled. If an Accepted Domain you add to the Exchange Admin
Center after July 1st is not secured with DNSSEC at the domain level (ex. contoso.com), then DNS resolution will work as usual. If an Accepted Domain you add to the EAC after July 1st is secured with DNSSEC, then DNSSEC will extend to the mx.microsoft DNS
record automatically and you will get the benefits of DNSSEC without having to take any further action. Any issues with DNSSEC can be addressed by disabling DNSSEC for the Accepted Domain (ex. contoso.com) via your DNS provider. </span><b style="-webkit-text-size-adjust: auto; box-sizing: inherit; color: rgb(237, 237, 237); font-family: "Segoe UI", "Segoe UI Web (West European)", "Segoe UI", -apple-system, BlinkMacSystemFont, Roboto, "Helvetica Neue", sans-serif; font-size: 14px;">What
you need to do to prepare:</b><span style="-webkit-text-size-adjust: auto; caret-color: rgb(179, 179, 179); color: rgb(179, 179, 179); font-family: "Segoe UI", "Segoe UI Web (West European)", "Segoe UI", -apple-system, BlinkMacSystemFont, Roboto, "Helvetica Neue", sans-serif; font-size: 14px; background-color: rgb(33, 33, 33);"> If
you have any automation in place, for example in workflows for Domain Setup, for MX record creation that expects A records for newly provisioned Accepted Domains to be provisioned in mail.protection.outlook.com, this automation needs to be updated by July
1st to use List serviceConfigurationRecords Graph API (List serviceConfigurationRecords). Use List serviceConfigurationRecords to retrieve the mailExchange value for your MX record. After July 1st, List serviceConfigurationRecords Graph API will be the only
source of truth for your Accepted Domains\u2019 MX record value. You will not be able to rely on the Accepted Domain\u2019s A record being provisioned in mail.protection.outlook.com after July 1st. If you are using automation that expects the record to end with mail.protection.outlook.com,
when you add a new Accepted Domain to the Exchange Admin Center after July 1st, mail flow may not work upon initial configuration and you will have to update your MX record to match what the Exchange Admin Center says for the domain or use the mailExchange
value returned by List serviceConfigurationRecords Graph API. If you expect this change to cause any issues for your organization, please share that feedback.\u201d</span></div>
<div><font color="#b3b3b3" face="Segoe UI, Segoe UI Web (West European), Segoe UI, -apple-system, BlinkMacSystemFont, Roboto, Helvetica Neue, sans-serif"><span style="caret-color: rgb(179, 179, 179); font-size: 14px; -webkit-text-size-adjust: auto; background-color: rgb(33, 33, 33);"><br>
</span></font></div>
<div><font color="#b3b3b3" face="Segoe UI, Segoe UI Web (West European), Segoe UI, -apple-system, BlinkMacSystemFont, Roboto, Helvetica Neue, sans-serif"><span style="caret-color: rgb(179, 179, 179); font-size: 14px; -webkit-text-size-adjust: auto; background-color: rgb(33, 33, 33);"><br id="lineBreakAtBeginningOfSignature">
</span></font>
<div dir="ltr">Sent from my iPhone</div>
</div>
</body>
</html>