A cloud-based identity and access management service for securing user authentication and resource access
To activate and verify a domain in Microsoft 365, use this path in the admin center:
- Go to Settings > Domains.
- Select Add domain.
- Enter the domain name and select Use this domain.
- Verify ownership:
- If the registrar supports automatic setup, sign in to the registrar, authorize Microsoft, and continue.
- Otherwise, add the TXT verification record manually at the DNS host.
- After the DNS record is added, complete verification.
If verification fails, check these common causes first:
- TXT record value is incorrect
- Make sure the value is copied exactly.
- A common mistake is missing the MS= part of the TXT record.
- DNS record was not fully saved
- Some DNS providers require an extra save or publish step.
- DNS changes have not propagated yet
- Verification can take a few minutes, and in some cases up to a few hours. In pilot guidance, DNS changes can take up to 72 hours.
- Too many unverified domains already exist
- Microsoft 365 allows up to 100 unverified domains. Verify or delete existing unverified domains, then try again.
- The domain already exists in the subscription
- If the portal shows Registering domain failed, no action is required because the domain already exists.
If the domain status shows an issue after adding records:
- Go to Setup > Domains.
- Check the Status column.
- Select the three dots (More actions) for the domain.
- Select Check health to see the exact DNS issue.
If the domain is already verified in another tenant, it cannot be verified in a different directory until it is removed from the existing tenant. In that case, use the admin center support path:
- In the Microsoft 365 admin center, select Help & Support or the headset icon.
- Enter a description such as setting up my domain.
- Review the results, then select Contact support if needed.
If this is a hybrid Exchange deployment and the error appears after adding the TXT or MX record, check whether the domain is already used in the on-premises Exchange federation trust as the primary federation organization identifier (ApplicationUri). In Exchange Management Shell, run Get-FederationTrust and confirm whether ApplicationUri matches the domain being verified.
References:
- Add a custom domain name
- Find and fix issues after adding your domain or DNS records
- An administrator can't add a domain to Microsoft 365, Azure, or Intune
- Find your domain registrar and DNS hosting provider
- An error occurred while working on your domain when you verify your domain in a hybrid deployment
- Cannot verify domain - Microsoft Q&A