ASD's Blueprint for Secure Cloud

DNS Settings

This section describes the DNS configuration associated with hybrid systems built according to guidance in ASD's Blueprint for Secure Cloud.

Estimated reading time: 3 minutes

MX records

MX records are not set within Azure or Exchange and are configured with the hosting provider.

Note, cloud-native MX configuration assumes Office 365 is not configured with a 3rd party gateway for mail flow.

Organisations that are required to route traffic through a 3rd party mail gateway will point MX record to the 3rd party gateway.

The following table describes the MX records to be configured per implementation type.

ImplementationDomainMX PreferencesMail Exchanger
Cloud-native<organisation.gov.au>10Organisation-com-au.mail.protection.outlook.com
Hybrid<organisation.gov.au>10<Organisation mx provider>

SPF and DMARC records

Note, SPF and DMARC DNS records are configured through the organisation’s DNS provider. DMARC and SPF configuration is unique to the organisation. The following configuration are included as examples.

The following table describes the SPF records to be configured per implementation type.

ImplementationDomainSPF RecordDMARC Policy
Cloud-native<organisation.gov.au>"v=spf1 include:spf.protection.outlook.com -all""v=DMARC1; p=reject; pct=100; rua=mailto:<rua reporting address>; ruf=mailto:<ruf reporting address>; fo=1"
Hybrid<organisation.gov.au>(Specific to gateway provider)"v=DMARC1; p=reject; pct=100; rua=mailto:<rua reporting address>; ruf=mailto:<ruf reporting address>; fo=1"

DKIM records

Note, DKIM DNS selector records are configured through the organisation’s DNS provider. Cloud-native configuration assumes DKIM signing is handled by Exchange Online Protection and not a third-party selector.

The following table describes the DKIM records configuration settings per implementation type.

ImplementationTypeDomainHost nameTTLPoints to address or value
Cloud-nativeCNAME<organisation.gov.au>selector1._domainkey5 Min.selector1-Organisation-gov-au._domainkey.<Organisationinitialdomain>.onmicrosoft.com.
Cloud-nativeCNAME<organisation.gov.au>selector2._domainkey5 Min.selector2-Organisation-gov-au._domainkey.<Organisation>.onmicrosoft.com.
HybridCNAME<organisation.gov.au><gateway provided selector>5 Min.<gateway provided selector>

DNS records

Note, the Autodiscover service external DNS entry is specific to the Hybrid implementation of the organisation. Once all mailboxes have been migrated to Office 365 within a Hybrid configuration this can be pointed as an alias to the Office 365 Autodiscover service using autodiscover.outlook.com.

Hybrid implementation types will require additional external DNS records depending on the hybrid implementation (classic or modern). The additional certificate requirements for hybrid can be located at - certificate requirements for hybrid deployments.

The following table describes the DNS record settings to be configured for Organisation.gov.au (default) per implementation type.

ImplementationTypePriorityHost namePoints to address or valueTTL
Cloud-nativeMX10Organisation DomainOrganisation-gov-au.mail.protection.outlook.com1 hour
HybridMX10Organisation DomainOrganisation mx provider address.1 hour
HybridCNAME-Organisation Edge Transport addressOrganisation edge transport gateway address.1 hour
HybridCNAME-Organisation CAS/EWS NAT addressOrganisation CAS/EWS NAT when using hybrid classic full.1 hour
AllTXT-Organisation DomainText string provided by Office 365 domain setup wizard.1 hour
Cloud-nativeCNAME-Autodiscover.Organisation.gov.auautodiscover.outlook.com1 hour
HybridCNAME-Autodiscover.Organisation.gov.auOrganisation autodiscover NAT address.1 hour

Do you have a suggestion on how the above page could be improved? Get in touch! ASD's Blueprint for Secure Cloud is an open source project, and we would love to get your input. Submit an issue on our GitHub, or send us an email at blueprint@asd.gov.au

Acknowledgement of Country icon

Acknowledgement of Country
We acknowledge the Traditional Owners and Custodians of Country throughout Australia and their continuing connections to land, sea and communities. We pay our respects to them, their cultures and their Elders; past, present and emerging. We also recognise Australia's First Peoples' enduring contribution to Australia's national security.

Authorised by the Australian Government, Canberra