Start with a classification problem, not a keyword match

For MSP prospecting, “uses Microsoft 365” sounds binary. Public infrastructure is not. A company can route mail directly through Microsoft, place Proofpoint or another secure email gateway in front of Microsoft 365, publish Microsoft Autodiscover records, use Entra ID for identity, or expose a mixture of signals left over from a migration. A useful detector therefore needs to separate direct evidence from supporting evidence.

The safest commercial question is not “Can I find the string Microsoft somewhere?” It is “Do the observable signals support Microsoft 365 strongly enough that I would use that classification to prioritize an account?”

Signal 1: direct Microsoft MX

When the public MX records point directly to Microsoft 365 mail protection, that is the cleanest email-routing signal. A direct Microsoft MX can support a high-confidence Workspace classification because the domain is publicly instructing other mail systems to deliver inbound mail through Microsoft infrastructure.

Important boundary

A gateway changes the picture. If MX points to Proofpoint, Mimecast, Hornetsecurity or another front-door provider, the underlying mailbox platform is no longer visible from MX alone.

Signal 2: Entra ID

Microsoft Entra ID evidence is valuable, but SecuTest deliberately does not treat Entra ID alone as proof that the organization uses Microsoft 365 for email. Entra can exist for identity, application access or mixed environments. It becomes more useful when it agrees with other Microsoft-specific signals.

Signal 3: Autodiscover

An Autodiscover record resolving toward Microsoft infrastructure is a strong secondary signal. Behind an email-security gateway, that signal can help explain the likely mailbox platform without pretending the gateway itself proves Microsoft 365.

Signal 4: Microsoft DKIM selectors

Published DKIM selectors associated with Microsoft can add another independent piece of evidence. This is especially useful when mail routing is abstracted by a gateway. As with every secondary signal, stale DNS and partial migrations are possible, so the result should be treated as supporting evidence rather than absolute truth.

Combine the signals

Observed patternReasonable classificationConfidence
Direct Microsoft MXMicrosoft 365High
Gateway MX + Entra + Microsoft AutodiscoverMicrosoft 365 behind gatewayStrong
Gateway MX + Microsoft DKIMLikely Microsoft 365 behind gatewayModerate to strong
Entra onlyMicrosoft identity signalInsufficient for email Workspace conclusion

Why this matters to an MSP

The classification is useful only when it changes the next sales action. Microsoft 365 may be relevant to backup, migration, licensing, identity, security hardening or managed email-security services. The external signal does not prove the prospect needs any of those services. It tells you which conversation is technically plausible.

A good outbound message therefore references the observable environment carefully: “We work with Microsoft 365 environments and noticed public signals consistent with M365 behind your current mail gateway” is materially different from claiming knowledge of an internal configuration you cannot see.

Microsoft 365 prospecting for MSPs →How to identify an email security provider →

Turn the signal into a prospecting workflow.

SecuTest attaches public infrastructure evidence to each prospect so your team can qualify the account without turning an inference into a claim.

Try for Free