Connect a .ie Domain to Microsoft 365 Email: DNS and Migration Checklist
You can keep a .ie domain with Hoster and use Microsoft 365 for Outlook and Exchange Online email. The registrar manages the domain registration. Your authoritative DNS provider publishes the records that point mail to Microsoft. Those can be different organisations, so the first task is to identify where the DNS zone actually lives.
This guide explains the setup and migration order for an Irish business. Microsoft 365 shows account-specific DNS values in its admin centre; copy those values rather than guessing from a generic example.
Before you start: identify the three systems
- Domain provider: manages registration, renewal, holder data and nameserver delegation. That may be Hoster.
- DNS provider: hosts the zone containing MX, TXT, CNAME and website records. It may be Hoster, Cloudflare, Wix or another provider.
- Mail provider: creates mailboxes, receives mail and signs outbound messages. Here it is Microsoft 365.
Find the authoritative nameservers in your domain dashboard or through DNS lookup. Edit records at the DNS provider, not automatically at the registrar. If you change nameservers later, copy the Microsoft 365 records into the new zone before switching.
Choose the domain and mailbox plan
Decide which people need licensed mailboxes and which shared or role addresses need a shared mailbox, alias or distribution group. Create the Microsoft 365 users and mailboxes before changing MX. Microsoft specifically warns that changing MX starts routing new inbound mail to Microsoft, so missing recipients can lose mail.
List hello@, sales@, accounts@ and other published addresses. Include contact forms, billing systems and help desks that send through the domain. Keep the previous mail service available during the migration.
Step 1: add and verify the custom domain
In the Microsoft 365 admin centre, add the .ie domain under domain settings. Microsoft supplies a TXT record or another verification method to prove you control the domain. Add the requested record at the authoritative DNS provider and wait for Microsoft to verify it.
Do not confuse verification with mail cutover. Adding a verification TXT record does not require you to change MX or move your website. If the verification fails, confirm that the record is in the correct zone, at the correct hostname, and visible from the authoritative nameserver.
Step 2: create all destination mailboxes
Create each user, shared mailbox, alias and group before routing live mail. Assign the required licences and test sign-in with MFA. If an address currently receives mail at the old provider but does not exist in Microsoft 365, messages sent after the MX change may bounce or go to the wrong place.
Inventory historical mail, calendars, contacts, forwarding rules, aliases, signatures and mobile devices. Decide what will be migrated and who will verify the result. A DNS change moves new message delivery; it does not copy old messages.
Step 3: add the Microsoft 365 DNS records
MX for inbound mail
Microsoft gives an MX target and priority for the domain. Publish the exact target shown in the tenant-specific setup page. Remove obsolete MX records only when the old service no longer needs to receive new mail. Avoid publishing two providers' MX records as an accidental “backup”; mail may reach the wrong provider.
SPF for authorised senders
Publish one SPF TXT record that covers Microsoft 365 and any legitimate third-party senders still in use. If an SPF record already exists, modify that record rather than creating a second one. The required policy depends on your sending architecture.
DKIM for signatures
Microsoft 365 can sign outgoing messages for the custom domain. Use the CNAME selectors and enablement steps shown in Microsoft Defender or the admin tools for your tenant. Confirm the domain reports DKIM as enabled and inspect a test message's authentication result. Do not assume the default tenant signature is the final custom-domain configuration.
DMARC for alignment and reporting
Publish a DMARC TXT record after inventorying all senders. Begin with a monitoring policy if you do not yet know which systems send on behalf of the domain, review aggregate reports, then tighten policy when legitimate mail passes. A strict policy before the sender inventory is complete can block invoices, help-desk replies or marketing mail.
Additional Microsoft 365 features can need CNAME, SRV or other records. Enable only the services you use and follow the current Microsoft wizard, because required values can differ by tenant and product.
Keep the website working
Changing MX should not change the website's A, AAAA or CNAME records. Changing nameservers, however, moves the entire DNS zone. If your .ie website is on Wix, Shopify or another host, leave its web records intact while adding Microsoft mail records. Confirm both the root domain and www still load over HTTPS after the mail cutover.
For a DNS provider move, use the safe nameserver checklist. The Cloudflare guide covers the case where Cloudflare hosts DNS and Microsoft hosts mail.
Cutover and testing plan
- Record the old MX, SPF, DKIM, DMARC and verification records.
- Create users and mailboxes in Microsoft 365.
- Verify the domain and publish the new authentication records.
- Agree a cutover window and communicate it to staff.
- Change MX to the exact Microsoft value shown for the tenant.
- Send test mail from outside accounts to every important address.
- Send replies and inspect message headers for SPF, DKIM and DMARC results.
- Check contact forms, billing mail, support systems and mobile clients.
- Keep the old provider accessible while historical mail and late deliveries are checked.
DNS caches may take time to update. Do not repeatedly change MX while investigating a single failed test. Query the authoritative DNS provider and a recursive resolver, then inspect Microsoft message trace and the previous provider's logs.
Common problems
Microsoft says the domain cannot be verified
The TXT record may be entered at the registrar while another provider hosts DNS, or the hostname may include the domain twice. Check the authoritative nameservers and the exact record returned by a direct query.
Website works but new mail bounces
Check that MX points to Microsoft, the recipient exists in Microsoft 365 and the domain is configured as an accepted domain. A working website only proves that web DNS is healthy.
Inbound works but outbound mail goes to spam
Check SPF, custom-domain DKIM, DMARC alignment and all third-party senders. Authentication is only part of deliverability; sending reputation and recipient filtering matter too.
Some messages still reach the old provider
Resolvers may have cached the old MX until its TTL expires. Keep the old service running during the transition and check whether a secondary MX record still points there.
Who should own the finished setup?
Record which organisation controls the domain, DNS zone, Microsoft tenant, renewal payment and recovery addresses. Enable MFA for both the domain and Microsoft administrator accounts. A future agency or employee should be able to update the configuration without guessing where the zone lives.
Use Hoster domain management for registration and delegation. If you are choosing a mailbox provider rather than committed to Microsoft 365, compare Hoster business email and the total support, storage and migration requirements for your team.