Steps
- 1
Get the CNAME values
In the Microsoft Defender portal, open Email authentication settings, choose DKIM and select your domain. Microsoft shows two CNAME records, selector1._domainkey and selector2._domainkey.
- 2
Publish both CNAMEs at your DNS host
Add them exactly as shown. They point at Microsoft-hosted keys, so Microsoft can rotate keys without you changing DNS again.
- 3
Wait for DNS
Allow time for the records to be visible. Most hosts update within minutes.
- 4
Enable signing
Back in the Defender portal, switch on signing for the domain. If Microsoft says the CNAMEs can't be found, wait a little longer and try again.
- 5
Check a message
Send an email to an outside mailbox and check the headers for dkim=pass with header.d set to your domain.
Using PowerShell
Connect-ExchangeOnline
New-DkimSigningConfig -DomainName example.com -Enabled $false
Get-DkimSigningConfig -Identity example.com | Format-List Selector1CNAME, Selector2CNAME
# publish both CNAMEs, then:
Set-DkimSigningConfig -Identity example.com -Enabled $trueDoing it with TenantWard
TenantWard reads the CNAME values from Exchange, publishes them to Cloudflare, GoDaddy or Route 53, waits for DNS and then enables signing, as one change with a backup and undo.
Questions
- Why does Microsoft 365 say DKIM CNAME records don't exist?
- Usually DNS hasn't caught up yet, the records were entered with the domain appended twice, or a proxy setting at the DNS host is altering them. Check the records with a DNS lookup and try again.
See where your company stands
Check a domain for free, then connect Microsoft 365 or Google Workspace for the full checkup. Every new workspace gets a 7-day trial, no card needed.