How do I set up DKIM in Microsoft 365?

Updated 9 October 2026 · 4 min read

To set up DKIM in Microsoft 365, you add two CNAME records (selector1 and selector2) at the company that hosts your DNS, then switch on DKIM signing for your domain in the Microsoft Defender portal. Until you do, Microsoft 365 doesn't sign your email with your own domain, so DKIM can't help it pass DMARC and more of it lands in junk.

DKIM is a digital signature added to every email you send. The receiving mail server looks up a public key in your DNS and checks the signature. If it matches, the receiver knows the email really came from your domain and wasn't changed on the way.

Before you start

You need two things:

  • An admin account for your Microsoft 365 organisation. This is your Microsoft 365 sign-in, not your domain or hosting login.
  • Access to your DNS. DNS is the set of records that tells the internet where your website and email live. It's usually managed where you bought your domain, such as GoDaddy, Crazy Domains or your web host.

Keep both open in separate browser tabs. You will move between them.

Step 1: Find your domain in the Defender portal

  1. Sign in at security.microsoft.com.
  2. Go to Email & collaboration → Policies & rules → Threat policies → Email authentication settings.
  3. Select the DKIM tab.

You will see a list of your domains. Each one has a Toggle (on or off) and a Status.

Microsoft moves menus from time to time. If you can't see this path, look for "Email authentication settings" in the Defender portal, or go straight to security.microsoft.com/authentication.

Step 2: Get your two CNAME records

Click on the name of your domain, for example yourbusiness.com.au. Click the name itself, not the checkbox beside it. A panel opens on the right.

  • If the status says No DKIM keys saved for this domain, select Create DKIM keys.
  • Microsoft then shows two records under Publish CNAMEs. Select Copy and paste them somewhere safe.

If you tried the toggle first, Microsoft shows a "Client error" message that contains the records. That's expected. Select OK, and the status changes to CnameMissing. Open the domain's panel to see the records in a tidier form.

Step 3: Add the two CNAME records to your DNS

A CNAME record points one name at another. Here, it points your domain to a key that Microsoft looks after for you. That's why you never paste in a long key yourself.

Add two records at your DNS host:

TypeHost namePoints to
CNAMEselector1._domainkeythe selector1 value Microsoft shows
CNAMEselector2._domainkeythe selector2 value Microsoft shows

The "points to" values follow one of two formats, depending on when your domain was added to Microsoft 365:

  • Domains added before May 2025: selector1-yourbusiness-com-au._domainkey.yourbusiness.onmicrosoft.com
  • Domains added from May 2025: selector1-yourbusiness-com-au._domainkey.yourbusiness.r-v1.dkim.mail.microsoft

In both, the dots in your domain become dashes, and the middle part is the name before ".onmicrosoft.com" in your original Microsoft 365 address. In the newer format, the single letter before "-v1" is set by Microsoft and varies. Don't guess it, and don't mix the two formats. Our report shows the records in the usual layout, but always use the exact values the Defender portal gives you.

Watch the host name. Some DNS hosts add your domain to the end automatically, so you type only selector1._domainkey. Others want the full name, selector1._domainkey.yourbusiness.com.au. If you type the full name into a host that adds it for you, you end up with the domain twice and Microsoft won't find the record.

Step 4: Switch on DKIM signing

DNS changes often show up within an hour, but can take up to 48 hours.

  1. Go back to the DKIM tab and open your domain's panel.
  2. Turn on Sign messages for this domain with DKIM signatures.
  3. Select OK on the message about synchronising.

If Microsoft finds your records, the toggle stays on and the status changes to Signing DKIM signatures for this domain. If you get an error, Microsoft can't see the records yet. Check for typos (the dashes and dots are easy to get wrong), check the host name wasn't doubled, wait a while and try again.

Repeat Steps 2 to 4 for every domain you send email from. Each one needs its own pair of records.

Step 5: Check it worked

Wait a few minutes after switching it on. Then send an email from your Microsoft 365 mailbox to an address outside your organisation. Microsoft doesn't add a DKIM signature to email sent between mailboxes in the same organisation, so testing with a colleague won't show anything.

The simplest check is to send that email to your free test address. Our report shows whether the DKIM signature passed and whether it was signed by yourbusiness.com.au itself. That second part matters: DMARC only counts DKIM when the signing domain matches the domain in your From address.

If you prefer to look yourself, open the message headers at the receiving end. Look for:

  • A DKIM-Signature line with d=yourbusiness.com.au and s=selector1 or s=selector2.
  • An Authentication-Results line that includes dkim=pass.

What this doesn't cover

These records sign email sent from your Microsoft 365 mailboxes only. If Xero sends your invoices, MYOB sends your statements or your website sends enquiry notifications, each of those services needs its own DKIM set up inside that service. Our test tells you which service sent the email, so you know which one to fix.

DKIM also works best alongside SPF and DMARC. If you haven't set those up yet, do them next.

Checked against: Microsoft Learn, How to use DKIM for email in your custom domain · GoDaddy Help, Enable and add DKIM to my domain for Microsoft 365 · RFC 6376, DomainKeys Identified Mail (DKIM) Signatures.

Questions people ask

Why does my DKIM record end in dkim.mail.microsoft instead of onmicrosoft.com?

Microsoft changed the record format for custom domains added from May 2025. Newer domains point to an address ending in dkim.mail.microsoft, while older domains keep the onmicrosoft.com format. Both are correct. Copy exactly what the Defender portal shows for your domain.

Microsoft says CnameMissing. What does that mean?

Microsoft can't see your two CNAME records yet. Check for typos in the dashes and dots, check the host name wasn't doubled up by your DNS host, then wait a little longer. DNS changes can take up to 48 hours.

Do I need to do this for every domain?

Yes. Each domain or subdomain you send from in Microsoft 365 needs its own two CNAME records and its own DKIM switch. Microsoft signs your original onmicrosoft.com address automatically.

Does this cover Xero and MYOB invoices too?

No. These records only sign email sent from your Microsoft 365 mailboxes. Xero, MYOB, your website and any newsletter service each need their own DKIM set up in that service.

How do I rotate my DKIM keys?

Open your domain on the DKIM tab and select Rotate DKIM keys. Microsoft switches to the other selector, and the new key starts signing after about four days. You don't need to change your DNS records.