Start with a classification problem, not a keyword match
For MSP prospecting, “uses Microsoft 365” sounds binary. Public infrastructure is not. A company can route mail directly through Microsoft, place Proofpoint or another secure email gateway in front of Microsoft 365, publish Microsoft Autodiscover records, use Entra ID for identity, or expose a mixture of signals left over from a migration. A useful detector therefore needs to separate direct evidence from supporting evidence.
The safest commercial question is not “Can I find the string Microsoft somewhere?” It is “Do the observable signals support Microsoft 365 strongly enough that I would use that classification to prioritize an account?”
Signal 1: direct Microsoft MX
When the public MX records point directly to Microsoft 365 mail protection, that is the cleanest email-routing signal. A direct Microsoft MX can support a high-confidence Workspace classification because the domain is publicly instructing other mail systems to deliver inbound mail through Microsoft infrastructure.
A gateway changes the picture. If MX points to Proofpoint, Mimecast, Hornetsecurity or another front-door provider, the underlying mailbox platform is no longer visible from MX alone.
Signal 2: Entra ID
Microsoft Entra ID evidence is valuable, but SecuTest deliberately does not treat Entra ID alone as proof that the organization uses Microsoft 365 for email. Entra can exist for identity, application access or mixed environments. It becomes more useful when it agrees with other Microsoft-specific signals.
Signal 3: Autodiscover
An Autodiscover record resolving toward Microsoft infrastructure is a strong secondary signal. Behind an email-security gateway, that signal can help explain the likely mailbox platform without pretending the gateway itself proves Microsoft 365.
Signal 4: Microsoft DKIM selectors
Published DKIM selectors associated with Microsoft can add another independent piece of evidence. This is especially useful when mail routing is abstracted by a gateway. As with every secondary signal, stale DNS and partial migrations are possible, so the result should be treated as supporting evidence rather than absolute truth.
Combine the signals
| Observed pattern | Reasonable classification | Confidence |
|---|---|---|
| Direct Microsoft MX | Microsoft 365 | High |
| Gateway MX + Entra + Microsoft Autodiscover | Microsoft 365 behind gateway | Strong |
| Gateway MX + Microsoft DKIM | Likely Microsoft 365 behind gateway | Moderate to strong |
| Entra only | Microsoft identity signal | Insufficient for email Workspace conclusion |
Why this matters to an MSP
The classification is useful only when it changes the next sales action. Microsoft 365 may be relevant to backup, migration, licensing, identity, security hardening or managed email-security services. The external signal does not prove the prospect needs any of those services. It tells you which conversation is technically plausible.
A good outbound message therefore references the observable environment carefully: “We work with Microsoft 365 environments and noticed public signals consistent with M365 behind your current mail gateway” is materially different from claiming knowledge of an internal configuration you cannot see.
Turn the signal into a prospecting workflow.
SecuTest attaches public infrastructure evidence to each prospect so your team can qualify the account without turning an inference into a claim.