Guides Microsoft 365 How to Generate Your DKIM Records in Microsoft 365

How to Generate Your DKIM Records in Microsoft 365

DKIM is a signature Microsoft adds to every email you send, proving the message really came from your domain and was not forged. Until it is set up, providers like Gmail are entitled to reject your mail outright, which is what a “Message blocked, the sender is unauthenticated” bounce means. Microsoft 365 does this differently from Google: instead of one record, you publish two, and Microsoft alternates between them.

Why this bit has to be you rather than us. The values are generated inside your own Microsoft 365 tenant and only an administrator of that account can see them. There is no way for us to work them out from the outside, even with access to your website or your domain. Once you have them, send them to us and adding them takes us about two minutes.

Before you start

  • You need to be a Microsoft 365 administrator, usually a Global Administrator. If the pages below tell you that you do not have access, you are not one, and whoever set up your email will need to do this or make you an admin.
  • This is a different login from your website. Being an admin of your site does not make you an admin of your email.
  • Allow about ten minutes.

Finding the screen

Microsoft has moved and renamed this page several times, so the reliable way in is to search rather than to follow a menu path:

  1. Go to security.microsoft.com and sign in with your administrator account.
  2. Type DKIM into the search box at the top and choose the DKIM result.

If you would rather navigate, at the time of writing it is under Email & collaboration, then Policies & rules, then Threat policies, then Email authentication settings, then the DKIM tab. On older tenants it may still live in the Exchange admin centre under Protection. If none of those match what you see, search for DKIM and tell us what you find.

Generating the two records

  1. You will see a list of your domains. Click the one your email addresses actually end in, not the long one ending in onmicrosoft.com.
  2. If it offers Create DKIM keys, click it.
  3. Microsoft now shows you two records to publish. Copy all of it. For each of the two you need the host name and the value it points to.

They will look something like this, where the middle part is specific to your organisation:

Host name Points to
selector1._domainkey selector1-yourdomain-com._domainkey.yourtenant.onmicrosoft.com
selector2._domainkey selector2-yourdomain-com._domainkey.yourtenant.onmicrosoft.com
Copy the values exactly. Do not try to work them out. They look predictable and they are not. The middle section is not simply your domain name with the dots swapped for dashes, and the onmicrosoft.com part is often nothing like your business name. We have seen a client whose domain is prime-land.ca where the correct value contains primeland-ca01c, and another whose tenant is a string of digits that appears nowhere else. Guessing produces records that look right and do nothing. Copy and paste, never retype.

What to send us

Reply with these and we will do the rest:

  1. The domain you are setting up.
  2. Both host names and both values, copied and pasted.

There is nothing secret in them, so pasting them into an email is fine. We will add them, confirm when they are live, and then tell you to go back and finish the job.

Then the step people miss

Publishing the records is not the same as switching DKIM on. Once both records are live, you have to return to that same DKIM screen, select your domain again, and turn on the switch that signs your messages. Until you do, Microsoft is not signing anything and your email can still be blocked, even though the records are sitting in your DNS looking perfect. If mail is still bouncing after the records were added, this is nearly always why.

The order matters. Publish both records first, wait for them to go live, then come back and switch it on. If you switch it on too early, Microsoft will refuse with a message about the records not being found, and you will have to come back anyway.

Why there are two

Microsoft periodically changes which key it signs with, alternating between the two. That is why both records must exist and both must stay in place permanently. If only one gets added, your email will authenticate correctly for a while and then mysteriously start failing when Microsoft switches over, which is a horrible problem to diagnose. Both, always.

If you would rather add them to your DNS yourself

Both are CNAME records, not TXT records. That trips people up, because the equivalent Google record is a TXT.

  • Type: CNAME
  • Host or Name: selector1._domainkey and then selector2._domainkey
  • Value, Target or Points to: the long value Microsoft gave for each
  • TTL: leave the default

Some DNS providers want just selector1._domainkey in the host field and some want the full address including your domain. If yours fills in the rest of the domain for you, do not type it twice.

How long it takes

Usually minutes, occasionally a few hours. Nothing about your email changes while you wait and there is no risk or downtime.

DKIM is one of two things, and SPF is the other

Gmail and Outlook want to see either SPF or DKIM pass, and ideally both. SPF is a separate record listing who is allowed to send email for your domain, and for Microsoft it normally includes spf.protection.outlook.com. It is worth us checking yours at the same time, because a common cause of blocked mail is a newsletter tool or booking system sending on your behalf that was never added.

One rule if you edit DNS yourself: a domain may only have one SPF record. Adding a second breaks both. Extra senders go inside the existing one.

If your email is still being blocked

Send us the bounce, and include the technical part rather than only the screenshot. The line beginning 550 is the useful one because it names which check failed. Also tell us:

  • The exact address you were sending from.
  • Whether that mail comes from a real Microsoft 365 mailbox, or from another account set up to send as that address. The second authenticates differently and is a common cause of this exact bounce.
  • Whether it fails for everyone or only certain recipients.

What we need if something fails

The domain, the bounce including the 550 line, and the sending address. If you have already created the keys, tell us whether you switched signing on and roughly when.

Still haven’t found what you’re looking for?

Let us know and we’ll do our best to help out!

Your Digital Marketing

Resource Centre

Have questions about paid ads, campaign optimisation, or platform features? Browse our knowledge base for step-by-step guides, FAQs, and expert insights to help you succeed.

Secret Link
SHARE YOUR CART