Connect DNS records at AWS to Microsoft 365

If AWS hosts your domain's DNS, follow the steps in this article to verify domain ownership and manually add the DNS records required for Microsoft 365 services such as email, Microsoft Teams, and device management. After you add these records at AWS, your domain is ready to work with Microsoft 365.

This article covers the creation of the following DNS records at AWS:

Service DNS record types
Domain verification TXT
Email MX, CNAME (Autodiscover), TXT (SPF)
Microsoft Teams SRV (2), CNAME (2)
Microsoft Intune/MDM CNAME (2)

Note

AWS is a non-Microsoft site. Microsoft doesn't control the AWS site. Additionally, AWS might change their website and tools so that the steps in this article are no longer valid. For support with AWS's site and tools, contact AWS support.

Before you begin

  • You must own a domain registered with AWS.
  • You must add the domain in the Microsoft 365 admin center. If the domain isn't added in the Microsoft 365 admin center, follow the steps in Add a domain to add your domain before you start adding DNS records at AWS.

Sign in to AWS to manage your domain's DNS records

To add DNS records at AWS, sign in to your AWS account and then go to the page where you can manage your domain's DNS records. Follow these steps to get there:

  1. To get started, go to your domains page at AWS and sign in.

  2. On the landing page, under Domains, select Registered domains.

  3. Under Domain Name, select the domain you want to set up in Microsoft 365.

    Important

    If a hosted zone for your domain doesn't exist, select Create hosted zone and complete the steps before moving to the next step.

    Screenshot of Registered Domains where you select the Domain Name.

  4. Select Manage DNS.

    Screenshot of selecting Manage DNS from the drop-down list.

  5. Under Domain name, select the domain name for the hosted zone version of the domain you want to set up in Microsoft 365.

    Screenshot of Hosted zones.

Add Microsoft 365 DNS records at AWS

To add the required DNS records at AWS for Microsoft 365 services, select the tab based on which DNS records you need to add:

Add a TXT record for domain ownership verification

Before you can use your domain with Microsoft 365, you need to prove you own the domain. Your ability to sign in to your account at your domain registrar and create the DNS record proves to Microsoft that you own the domain. This process involves creating a TXT record at your domain registrar with a specific value that Microsoft can look for. When Microsoft finds the record with the correct value, your domain is verified. The TXT record is used only to verify that you own your domain. It doesn't affect anything else and can be deleted once domain verification is complete.

Note

The procedures in this section assume that you started the process of adding a domain, but you didn't verify domain ownership yet.

To add the TXT record for domain verification at AWS, follow these steps:

  1. Get the TXT value specific for your domain from the Microsoft 365 admin center. For help on finding the value of your TXT record in the Microsoft 365 admin center, see Gather the information you need to create DNS records.

  2. If you're not already signed in to the AWS Hosted Zones page and selected the domain you want to add the TXT record for, follow the steps in Sign in to AWS to manage your domain's DNS records to get there.

  3. Select Create record.

    Screenshot of where you select Create record.

  4. In the boxes for the new record, enter the values from the following table:

    Record name Record type Value TTL (seconds) Routing policy
    {Leave empty} TXT MS=msXXXXXXXX 1800 Simple routing
    • In the Value field, replace MS=msXXXXXXXX with the TXT value you gathered earlier from the Microsoft 365 admin center. The value shown in the table is only an example.
    • Select the Record type and Routing policy values from the drop-down menus.
  5. Select Create records.

    Screenshot of where you select Create records to add a domain verification TXT record.

Once you add the record at your domain registrar's site, go back to Microsoft and request a search for the record. When Microsoft finds the correct TXT record, your domain is verified.

To verify the record in Microsoft 365:

  1. Sign in to the Microsoft 365 admin center.

  2. From the left navigation bar, select … Show all, and then select Settings to expand it.

  3. Under Settings, select Domains.

  4. In the Domains page, select the domain that you're verifying, and select Start setup.

    Screenshot of selecting Start setup.

  5. Select Continue.

  6. On the Verify domain page, select Verify.

Support

If you don't find what you're looking for, check the Domains FAQ.

Tip

Some configuration tasks might be complex to perform. For technical support, follow these steps:

  1. Sign in to the Microsoft 365 admin center.
  2. At the bottom right, select Help & Support.
  3. In the Support Assistant pane that opens, enter your question.
  4. Review the results. If you still have questions, select Contact support.

To learn about your options for contacting support, see Get support for Microsoft 365 for business.