How to enable DKIM in Microsoft 365

Microsoft 365 signs mail with its own onmicrosoft.com domain by default. For DMARC to pass on DKIM, it needs to sign with your domain, which takes two DNS records and a switch.

Updated October 4, 2026

Steps

  1. 1

    Get the CNAME values

    In the Microsoft Defender portal, open Email authentication settings, choose DKIM and select your domain. Microsoft shows two CNAME records, selector1._domainkey and selector2._domainkey.

  2. 2

    Publish both CNAMEs at your DNS host

    Add them exactly as shown. They point at Microsoft-hosted keys, so Microsoft can rotate keys without you changing DNS again.

  3. 3

    Wait for DNS

    Allow time for the records to be visible. Most hosts update within minutes.

  4. 4

    Enable signing

    Back in the Defender portal, switch on signing for the domain. If Microsoft says the CNAMEs can't be found, wait a little longer and try again.

  5. 5

    Check a message

    Send an email to an outside mailbox and check the headers for dkim=pass with header.d set to your domain.

Using PowerShell

Connect-ExchangeOnline
New-DkimSigningConfig -DomainName example.com -Enabled $false
Get-DkimSigningConfig -Identity example.com | Format-List Selector1CNAME, Selector2CNAME
# publish both CNAMEs, then:
Set-DkimSigningConfig -Identity example.com -Enabled $true

Doing it with TenantWard

TenantWard reads the CNAME values from Exchange, publishes them to Cloudflare, GoDaddy or Route 53, waits for DNS and then enables signing, as one change with a backup and undo.

Questions

Why does Microsoft 365 say DKIM CNAME records don't exist?
Usually DNS hasn't caught up yet, the records were entered with the domain appended twice, or a proxy setting at the DNS host is altering them. Check the records with a DNS lookup and try again.

See where your company stands

Check a domain for free, then connect Microsoft 365 or Google Workspace for the full checkup. Every new workspace gets a 7-day trial, no card needed.