---
title: "Microsoft 365: enable DKIM"
description: "Enable DKIM for Microsoft 365 custom domains and publish CNAME records as instructed."
translationKey: "email-microsoft-365-dkim"
tags: [microsoft, office365, dkim]
publishedAt: "2026-05-01"
lastReviewedAt: "2026-05-01"
indexable: true
faq:
  - question: "Why does Microsoft 365 use CNAME records for DKIM?"
    answer: "Microsoft publishes rotating selector targets via CNAMEs so they can manage keys centrally while your DNS stays aligned with their prescribed hostnames."
  - question: "What breaks DKIM first after enabling it in the portal?"
    answer: "Misspelled CNAME hostnames or targets in DNS—copy Microsoft’s values exactly and wait for propagation before judging signature failures."
---
> **Canonical:** https://formreceipt.com/docs/email-deliverability/microsoft-365-dkim

## Domain registration

In the Microsoft Defender portal or classic Exchange admin experiences, register the domain for DKIM and note the **CNAME** targets Microsoft provides.

## DNS publishing

Create the exact hostnames and targets Microsoft lists—typos here break verification.

## Testing

Send messages through Microsoft 365 and inspect authentication headers on received copies from a mailbox that shows full headers.
