Microsoft 365 DKIM
Microsoft 365 DKIM uses selector CNAMEs (commonly selector1 and selector2) published in your DNS and enabled in the Microsoft 365 Defender / Exchange admin experience.
What to configure
Create CNAMEs to the Microsoft-published keys for your domain, enable DKIM signing, and confirm Authentication-Results shows dkim=pass with aligned d=.
selector1._domainkey → CNAME to Microsoft
selector2._domainkey → CNAME to MicrosoftCommon M365 pitfalls
Assuming the Microsoft 365 admin center publishes DMARC; forgetting printer/scanner SMTP; adding too many ESP includes; disabling DKIM after domain changes.
Validation steps
Send external test messages, inspect Authentication-Results, run DMARC/SPF/DKIM checkers, and confirm aggregate reports arrive.
How QuickDMARC helps
QuickDMARC monitors M365 domains, highlights unaligned SaaS, and supports Managed DMARC for policy changes without ticket ping-pong.
Frequently asked questions
Does Microsoft host my DMARC record?
No. You publish _dmarc at your DNS provider.
Is SPF include enough?
No. Enable DKIM and publish DMARC with reporting.
Deep-dive setup?
See the Microsoft 365 DMARC setup guide.