Microsoft 365 publishes DKIM keys through two CNAME records, not TXT. Mail from your initial onmicrosoft.com domain is signed automatically; a custom domain needs these records and the toggle switched on.
Get-DkimSigningConfig -Identity example.com | Format-List Selector1CNAME,Selector2CNAME in Exchange Online PowerShell. Microsoft stresses the values differ per organization.selector1._domainkey.example.com. CNAME selector1-example-com._domainkey.contoso.onmicrosoft.com. selector2._domainkey.example.com. CNAME selector2-example-com._domainkey.contoso.onmicrosoft.com.These targets are illustrative; older tenants and newer ones can have different target formats, so always copy yours from Microsoft.
Set-DkimSigningConfig -Identity example.com -Enabled $true.Your DNS host may append the domain automatically; if so, enter only selector1._domainkey.
Not sure what your domain publishes today? The checker reads your live DNS and shows what is missing. If you would rather skip the trial and error, the $29 Email Fix Pack gives you ready-to-paste records for your domain; see a sample pack.