Email Fix Pack

How to set up DKIM in Microsoft 365

Microsoft 365 publishes DKIM keys through two CNAME records, not TXT. Mail from your initial onmicrosoft.com domain is signed automatically; a custom domain needs these records and the toggle switched on.

Steps

  1. Get your exact values from the Defender portal (Email & collaboration, Policies & rules, Threat policies, Email authentication settings, DKIM tab) or with Get-DkimSigningConfig -Identity example.com | Format-List Selector1CNAME,Selector2CNAME in Exchange Online PowerShell. Microsoft stresses the values differ per organization.
  2. At your DNS host add two CNAME records, using the format Microsoft documents:
    selector1._domainkey.example.com.  CNAME  selector1-example-com._domainkey.contoso.onmicrosoft.com.
    selector2._domainkey.example.com.  CNAME  selector2-example-com._domainkey.contoso.onmicrosoft.com.
    These targets are illustrative; older tenants and newer ones can have different target formats, so always copy yours from Microsoft.
  3. After DNS updates, open the domain on the DKIM tab and slide the toggle to Enabled, or run Set-DkimSigningConfig -Identity example.com -Enabled $true.
  4. Send a test message and confirm DKIM passes in the message headers.

Your DNS host may append the domain automatically; if so, enter only selector1._domainkey.

Check your domain

Not sure what your domain publishes today? The checker reads your live DNS and shows what is missing. If you would rather skip the trial and error, the $29 Email Fix Pack gives you ready-to-paste records for your domain; see a sample pack.

Check your domain free

Sources

  • Microsoft Learn: Use DKIM for email in your custom domain

More email delivery fixes

Email Fix Pack

Terms · Privacy · Refunds