Set up DKIM for Microsoft 365

Defender portal → Email authentication settings → DKIM

  1. Open security.microsoft.com and sign in as a global or security administrator.
  2. Navigate to Email & collaboration → Policies & rules → Threat policies → Email authentication settings → DKIM.
  3. Select the domain and read the two CNAME targets shown.
  4. Publish CNAMEs at selector1._domainkey and selector2._domainkey pointing at those targets.
  5. Set Sign messages for this domain with DKIM signatures to Enabled.

Confirm it worked

DNS changes take time to propagate. Check the record once you have published it.

Leave the selector blank and we will probe the selectors that common providers use.

Microsoft 365 official documentation

Other Microsoft 365 guides