- Home
- Free tools
- Microsoft 365 tenant lookup
What does Microsoft know about this domain?
Tenant ID, data region, whether sign-in is managed or federated, and every DNS record Microsoft 365 relies on: Exchange Online routing, SPF, DKIM, DMARC, Autodiscover, Entra device registration and Intune enrolment. Public endpoints only; nothing is signed in to.
Where the answers come from, and what they mean.
Tenant and identity
Microsoft's sign-in service answers two public questions for any domain: is it verified in a tenant, and how do its users authenticate. From that the tool shows the tenant ID (needed for cross-tenant access settings, B2B invitations and many admin scripts), the data region where the tenant's core data lives (Oceania for Australian tenants), the tenant's display name, and whether sign-in is managed (Entra ID authenticates directly) or federated (redirected to AD FS, Okta or another identity provider).
Exchange Online and email authentication
Whether inbound mail goes straight to Exchange Online Protection or through a third-party filter first, whether SPF includes Microsoft, whether the two DKIM selectors Microsoft 365 uses are published, and the DMARC policy. DKIM signing is off by default for custom domains in Microsoft 365, which is why so many tenants fail it.
Clients and devices
- Autodiscover lets Outlook and phones configure themselves. Without it, profiles are set up by hand or slowly.
- enterpriseregistration is required for hybrid or Entra-joined devices whose users sign in with this domain.
- enterpriseenrollment lets Windows devices find Intune automatically during setup.
- Skype for Business records (lyncdiscover, sip, _sip, _sipfederationtls) are no longer needed for Teams and can be removed.
Common questions
Is it safe that this information is public?
The lookup says our domain is not in a tenant, but we use Microsoft 365.
We are federated. Is that a problem?
Get the tenant reviewed against a written baseline.
Identity, conditional access, device compliance, mail flow, licensing, backup and the DNS underneath it, reviewed and documented, with a roadmap you can act on with or without us.