To set up DKIM in Microsoft 365, you add two CNAME records (selector1 and selector2) at the company that hosts your DNS, then switch on DKIM signing for your domain in the Microsoft Defender portal. Until you do, Microsoft 365 doesn't sign your email with your own domain, so DKIM can't help it pass DMARC and more of it lands in junk.
DKIM is a digital signature added to every email you send. The receiving mail server looks up a public key in your DNS and checks the signature. If it matches, the receiver knows the email really came from your domain and wasn't changed on the way.
Before you start
You need two things:
- An admin account for your Microsoft 365 organisation. This is your Microsoft 365 sign-in, not your domain or hosting login.
- Access to your DNS. DNS is the set of records that tells the internet where your website and email live. It's usually managed where you bought your domain, such as GoDaddy, Crazy Domains or your web host.
Keep both open in separate browser tabs. You will move between them.
Step 1: Find your domain in the Defender portal
- Sign in at security.microsoft.com.
- Go to Email & collaboration → Policies & rules → Threat policies → Email authentication settings.
- Select the DKIM tab.
You will see a list of your domains. Each one has a Toggle (on or off) and a Status.
Microsoft moves menus from time to time. If you can't see this path, look for "Email authentication settings" in the Defender portal, or go straight to security.microsoft.com/authentication.
Step 2: Get your two CNAME records
Click on the name of your domain, for example yourbusiness.com.au. Click the name itself, not the checkbox beside it. A panel opens on the right.
- If the status says No DKIM keys saved for this domain, select Create DKIM keys.
- Microsoft then shows two records under Publish CNAMEs. Select Copy and paste them somewhere safe.
If you tried the toggle first, Microsoft shows a "Client error" message that contains the records. That's expected. Select OK, and the status changes to CnameMissing. Open the domain's panel to see the records in a tidier form.
Step 3: Add the two CNAME records to your DNS
A CNAME record points one name at another. Here, it points your domain to a key that Microsoft looks after for you. That's why you never paste in a long key yourself.
Add two records at your DNS host:
| Type | Host name | Points to |
|---|---|---|
| CNAME | selector1._domainkey | the selector1 value Microsoft shows |
| CNAME | selector2._domainkey | the selector2 value Microsoft shows |
The "points to" values follow one of two formats, depending on when your domain was added to Microsoft 365:
- Domains added before May 2025:
selector1-yourbusiness-com-au._domainkey.yourbusiness.onmicrosoft.com - Domains added from May 2025:
selector1-yourbusiness-com-au._domainkey.yourbusiness.r-v1.dkim.mail.microsoft
In both, the dots in your domain become dashes, and the middle part is the name before ".onmicrosoft.com" in your original Microsoft 365 address. In the newer format, the single letter before "-v1" is set by Microsoft and varies. Don't guess it, and don't mix the two formats. Our report shows the records in the usual layout, but always use the exact values the Defender portal gives you.
Watch the host name. Some DNS hosts add your domain to the end automatically, so you type only selector1._domainkey. Others want the full name, selector1._domainkey.yourbusiness.com.au. If you type the full name into a host that adds it for you, you end up with the domain twice and Microsoft won't find the record.
Step 4: Switch on DKIM signing
DNS changes often show up within an hour, but can take up to 48 hours.
- Go back to the DKIM tab and open your domain's panel.
- Turn on Sign messages for this domain with DKIM signatures.
- Select OK on the message about synchronising.
If Microsoft finds your records, the toggle stays on and the status changes to Signing DKIM signatures for this domain. If you get an error, Microsoft can't see the records yet. Check for typos (the dashes and dots are easy to get wrong), check the host name wasn't doubled, wait a while and try again.
Repeat Steps 2 to 4 for every domain you send email from. Each one needs its own pair of records.
Step 5: Check it worked
Wait a few minutes after switching it on. Then send an email from your Microsoft 365 mailbox to an address outside your organisation. Microsoft doesn't add a DKIM signature to email sent between mailboxes in the same organisation, so testing with a colleague won't show anything.
The simplest check is to send that email to your free test address. Our report shows whether the DKIM signature passed and whether it was signed by yourbusiness.com.au itself. That second part matters: DMARC only counts DKIM when the signing domain matches the domain in your From address.
If you prefer to look yourself, open the message headers at the receiving end. Look for:
- A DKIM-Signature line with
d=yourbusiness.com.auands=selector1ors=selector2. - An Authentication-Results line that includes
dkim=pass.
What this doesn't cover
These records sign email sent from your Microsoft 365 mailboxes only. If Xero sends your invoices, MYOB sends your statements or your website sends enquiry notifications, each of those services needs its own DKIM set up inside that service. Our test tells you which service sent the email, so you know which one to fix.
DKIM also works best alongside SPF and DMARC. If you haven't set those up yet, do them next.
Checked against: Microsoft Learn, How to use DKIM for email in your custom domain · GoDaddy Help, Enable and add DKIM to my domain for Microsoft 365 · RFC 6376, DomainKeys Identified Mail (DKIM) Signatures.