To add DKIM in GoDaddy, open your domain's DNS records and add the CNAME or TXT records your email service gives you, such as Microsoft 365's selector1._domainkey and selector2._domainkey. DMARC is one TXT record with the Name _dmarc, and if GoDaddy already created one for you, you edit it instead of adding another.
DKIM is a digital signature on every email you send, checked against a key in your DNS, which proves the email really came from your domain. DMARC tells receivers what to do with email that fails your checks, and sends you reports about who is sending as you. SPF is the third record, and our guide to adding an SPF record in GoDaddy covers it.
The records you'll add
| Record | Type | Name in GoDaddy | Value |
|---|---|---|---|
| DKIM (Microsoft 365) | CNAME | selector1._domainkey | Copied from the Defender portal |
| DKIM (Microsoft 365) | CNAME | selector2._domainkey | Copied from the Defender portal |
| DKIM (other services) | CNAME or TXT | The name the service gives you, without your domain | Copied from that service |
| DMARC | TXT | _dmarc | v=DMARC1; p=none; rua=mailto:dmarc-reports@yourbusiness.com.au |
Never type DKIM values by hand. They're unique to your account, so copy and paste them exactly.
Step 1: Check GoDaddy manages your DNS
GoDaddy only controls your DNS if your domain uses GoDaddy's nameservers (the servers that tell the internet where your DNS lives). If it uses another company's nameservers, often because a web designer or host moved your DNS, records you add in GoDaddy do nothing. Add the same records at that company instead.
To check, select your domain, then DNS, then Nameservers. If it says you're using your own nameservers, your DNS is managed somewhere else.
Step 2: Get the Name field right
GoDaddy's Name field takes only the part before your domain. GoDaddy adds yourbusiness.com.au to the end automatically.
- For DMARC, enter
_dmarc. - For Microsoft 365 DKIM, enter
selector1._domainkey, thenselector2._domainkey.
If your email service shows a full host name such as selector1._domainkey.yourbusiness.com.au, drop the .yourbusiness.com.au part before you paste it. Otherwise you'll end up with the domain twice.
Leave TTL (how long other servers remember the record) at GoDaddy's default of 1 hour.
Step 3: Add your DKIM records
Microsoft 365. Microsoft creates the keys, and you publish them in GoDaddy.
- In the Microsoft Defender portal, go to Email & collaboration → Policies & rules → Threat policies → Email authentication settings → DKIM.
- Select your domain's name (not the checkbox beside it). If it asks, choose Create DKIM keys, then copy the two CNAME records it shows.
- In GoDaddy, open your Domain Portfolio, select your domain, then select DNS.
- Select Add New Record and set Type to CNAME.
- Enter
selector1._domainkeyas the Name and paste Microsoft's first value into Value. - Select Add More Records and repeat for
selector2._domainkey. - Select Save All Records.
Microsoft's values end in either .onmicrosoft.com or .dkim.mail.microsoft, depending on when your domain was added. Once the records are live, go back to the Defender portal and turn on Sign messages for this domain with DKIM signatures. Our guide to setting up DKIM in Microsoft 365 covers that part.
Other services such as your website's email service or a newsletter tool give you either CNAME or TXT records. Add the type they show, with only the prefix in Name. GoDaddy allows TXT values up to 1,024 characters, which fits a normal DKIM key.
If GoDaddy refuses a CNAME because the name is already in use, there's an old record at that name. Edit or delete the old one first, because a CNAME can't share its name with any other record.
If your domain has GoDaddy's Domain Protection, GoDaddy asks for a verification code before it saves.
Step 4: Add or edit your DMARC record
First, look through your TXT records for one named _dmarc. GoDaddy says that since April 2025 every domain bought or transferred in gets a default DMARC record with a quarantine policy. A domain can only have one DMARC record, so if there's one already, select Edit on it rather than adding another.
If there's none:
- Select Add New Record and set Type to TXT.
- Enter
_dmarcas the Name. - Enter this as the Value:
v=DMARC1; p=none; rua=mailto:dmarc-reports@yourbusiness.com.au
- Leave TTL at the default and select Save.
p=none is monitoring mode, so nothing changes for your email yet. The rua address is where receivers send daily reports about who is sending as you. Change it to a mailbox you actually read. Once the reports show all your genuine email passing, change p=none to p=quarantine.
GoDaddy's own instructions start at p=quarantine. That's fine once SPF and DKIM pass for your own domain. If they don't yet, quarantine tells receivers to put your own failing email in junk. That's why our reports start at p=none.
Step 5: Check it worked
GoDaddy says most DNS changes take effect within an hour, but can take up to 48 hours. Once they've had time, send an email to your free test address. The report checks SPF, DKIM, DMARC and alignment (whether those checks passed for your own domain), gives a verdict for Gmail, Google Workspace, Outlook.com, Microsoft 365 and Yahoo, and shows the exact record to change if anything is still wrong.
Common mistakes
- Typing the full host name into Name, so the domain appears twice.
- Adding a second DMARC record instead of editing GoDaddy's default one.
- Adding records in GoDaddy when the nameservers point elsewhere. They have no effect.
Checked against: GoDaddy Help, Add a CNAME record · GoDaddy Help, Add a TXT record · GoDaddy Help, Enable and add DKIM to my domain for Microsoft 365 · GoDaddy Help, Add a DMARC record to my domain for Microsoft 365 · GoDaddy Help, Manage DNS records · GoDaddy Blog, Enhancing domain security with DMARC · Microsoft Learn, How to use DKIM for email in your custom domain.