Set up DKIM for Microsoft 365
Defender portal → Email authentication settings → DKIM
- Open security.microsoft.com and sign in as a global or security administrator.
- Navigate to Email & collaboration → Policies & rules → Threat policies → Email authentication settings → DKIM.
- Select the domain and read the two CNAME targets shown.
- Publish CNAMEs at selector1._domainkey and selector2._domainkey pointing at those targets.
- Set Sign messages for this domain with DKIM signatures to Enabled.
Confirm it worked
DNS changes take time to propagate. Check the record once you have published it.
Microsoft 365 official documentation