Services AI Systems & Intelligent Automation Cloud Platforms & Enterprise Architecture Cybersecurity, Identity & Governance Systems Integration & Business Automation Intelligent Web Platforms Infrastructure & Networking Managed Technology Services Case Study Industries Free tools About Contact Talk to an Architect
  1. Home
  2. Free tools
  3. Microsoft 365 tenant lookup
Tool 06 · Microsoft 365

What does Microsoft know about this domain?

Tenant ID, data region, whether sign-in is managed or federated, and every DNS record Microsoft 365 relies on: Exchange Online routing, SPF, DKIM, DMARC, Autodiscover, Entra device registration and Intune enrolment. Public endpoints only; nothing is signed in to.

Results are indicative and based on public DNS and HTTP responses at the moment you run the check. They are not a security audit or a compliance finding. See the terms.

Reading the result

Where the answers come from, and what they mean.

Tenant and identity

Microsoft's sign-in service answers two public questions for any domain: is it verified in a tenant, and how do its users authenticate. From that the tool shows the tenant ID (needed for cross-tenant access settings, B2B invitations and many admin scripts), the data region where the tenant's core data lives (Oceania for Australian tenants), the tenant's display name, and whether sign-in is managed (Entra ID authenticates directly) or federated (redirected to AD FS, Okta or another identity provider).

Exchange Online and email authentication

Whether inbound mail goes straight to Exchange Online Protection or through a third-party filter first, whether SPF includes Microsoft, whether the two DKIM selectors Microsoft 365 uses are published, and the DMARC policy. DKIM signing is off by default for custom domains in Microsoft 365, which is why so many tenants fail it.

Clients and devices

  • Autodiscover lets Outlook and phones configure themselves. Without it, profiles are set up by hand or slowly.
  • enterpriseregistration is required for hybrid or Entra-joined devices whose users sign in with this domain.
  • enterpriseenrollment lets Windows devices find Intune automatically during setup.
  • Skype for Business records (lyncdiscover, sip, _sip, _sipfederationtls) are no longer needed for Teams and can be removed.

Common questions

Is it safe that this information is public?
Yes. Every Microsoft 365 tenant answers these queries for any domain; it is how other tenants, mail servers and devices find you. The tool shows nothing an attacker could not see, and it helps you notice gaps before they do.
The lookup says our domain is not in a tenant, but we use Microsoft 365.
The domain may be added but not verified, or you may be signing in with a different domain (for example the onmicrosoft.com default). Check Settings › Domains in the Microsoft 365 admin centre.
We are federated. Is that a problem?
Federation works, but every sign-in depends on the identity provider being up and reachable. Most organisations now prefer cloud authentication with password hash synchronisation, which removes that dependency and enables Microsoft's leaked-credential detection.
Next step

Get the tenant reviewed against a written baseline.

Identity, conditional access, device compliance, mail flow, licensing, backup and the DNS underneath it, reviewed and documented, with a roadmap you can act on with or without us.