Connecting Microsoft Azure DNS

How to connect your Microsoft Azure DNS to DMARCER so it can read your DNS zones and apply the fixes you approve.

Published 22 Jul 2026 1

Connecting Azure DNS lets DMARCER read your DNS zones and apply the fixes you approve, so you do not have to make the changes by hand.

Step 1: Create a service principal in Microsoft Entra

  1. In Microsoft Entra, create a service principal (an app registration) for DMARCER.
  2. Give it the 'DNS Zone Contributor' role on the resource group that holds your DNS zones.
  3. Make a note of your Entra tenant ID, the service principal's client ID and client secret, your subscription ID, and the resource group name. You will need these in the next step.

Step 2: Add the integration in DMARCER

  1. Open Integrations and click Add.
  2. Choose DNS, then Azure DNS.
  3. Enter the tenant ID, client ID, client secret, subscription ID and resource group.
  4. Give the connection a friendly name, leave test mode and zone sync ticked, then click Connect.

DMARCER safely encrypts your credentials, checks the connection and finds your zones. While test mode is on, nothing is changed in your real DNS.

Step 3: Go live

Have a look through the zones that were found, then switch the integration from Test to Live so that approved changes can be applied.

What happens next

With Azure DNS connected, DMARCER can apply fixes for you at the click of a button and look after SPF, MTA-STS and DKIM for your zones.

Was this article useful?

Be the first to vote.
Got feedback for our team? Send us a comment

Related articles