Blog

Set up DKIM for Office 365 in Simple Steps

Image for DKIM set up for office 365

If you are sending emails through Microsoft 365, you need more than just a working email system. You need trust. Without proper authentication, your emails can land in spam or, worse, your domain can be misused by attackers.

That is where DKIM comes in. It helps verify that your emails are genuine and have not been altered during delivery. In this guide, you will learn how to setup DKIM in office 365 in simple steps, even if you are not very technical.

We will walk you through everything from prerequisites to final verification, so you can secure your domain and improve email delivery without confusion.

What is DKIM?

DKIM (DomainKeys Identified Mail) is an email authentication method that helps prove that your emails are genuine and have not been changed during delivery. In simple terms, DKIM adds a digital signature to every email you send. When an email reaches the recipient’s inbox, the receiving server checks the DKIM signature. If everything matches, the email is considered safe. If not, it may be marked as suspicious or spam.

If you use Microsoft services, properly configuring DKIM in Office 365 helps protect your domain from misuse by attackers. It also improves how inbox providers trust your emails.

Why Should Domain Owners Configure DKIM for Office 365

Here’s how a proper DKIM setup for Office 365 adds a layer of trust, security, and control to your emails:

Better Email Trust and Delivery

When you set up DKIM in Office 365, your emails carry a verified signature that inbox providers can check. This makes your emails look more reliable and reduces the chances of them being flagged as spam. Over time, this also improves your sender reputation, which directly impacts your email deliverability.

Protection Against Spoofing

Email spoofing is a common tactic used by attackers to send fake emails using your domain name. DKIM makes this much harder because every email must pass a signature check. If someone tries to send an unauthorized email, it will fail verification, helping protect your domain and your recipients.

Supports DMARC Implementation

DKIM plays an important role in DMARC authentication. Without DKIM, your DMARC setup becomes weaker and less effective. When DKIM is properly configured, it helps DMARC accurately verify your emails and apply your policies, giving you better control over your domain’s email usage.

Maintains Email Integrity

DKIM ensures that your email content stays unchanged from sender to receiver. If any part of the email is modified during transit, the DKIM signature breaks. This signals to the receiving server that the email may have been tampered with, adding an extra layer of security.

Improves Brand Reputation

When your emails consistently pass authentication checks, recipients begin to trust your domain more. This trust builds your brand image and increases engagement with your emails. It also reduces complaints and improves overall email performance.

Prerequisites for DKIM Setup in Office 365

Before you begin the Office 365 DKIM setup, it is important to make sure a few basic things are already in place. Without these, your setup may fail or get delayed.

  • Admin access to Microsoft 365: You need the right permissions to configure DKIM. Usually, a Global Administrator or Exchange Administrator role is required to access the DKIM settings and enable signing.
  • Custom domain added and verified: DKIM is required only for custom domains (like yourcompany.com). Your domain must already be added and verified in Microsoft 365 before you can configure DKIM for it.
  • Access to your DNS provider: You will need to create CNAME records during setup. For that, you must have access to your domain registrar or DNS hosting provider, where your domain records are managed.
  • SPF record already configured: DKIM works best when combined with SPF. In fact, SPF should already be set up for your domain before you enable DKIM, as both together strengthen your email authentication.
  • Basic understanding of DNS changes: Since you will be adding CNAME records, it helps to understand how DNS works. Even small mistakes, such as typos, can cause DKIM configuration to fail or delay verification.

Once these prerequisites are in place, the DKIM Office 365 setup process becomes much smoother and faster, with fewer chances of errors.

How to Set Up DKIM in Office 365 (Step-by-Step)

Setting up DKIM in Microsoft 365 may sound technical, but it is actually a simple process if you follow each step carefully. The DKIM Office 365 setup mainly involves retrieving your records, adding them to DNS, enabling DKIM, and verifying it. Let’s break it down.

Step 1: Get DKIM CNAME Records from Microsoft 365

First, you need to collect the DKIM records generated by Microsoft.

  • Log in to the Microsoft Defender portal
  • Go to Email & Collaboration > Policies & Rules > Threat policies
  • Open Email Authentication Settings
  • Click on the DKIM tab
  • Select your custom domain

Here, you will see two CNAME records (selector1 and selector2). These are unique to your domain, so copy them exactly as shown.

Step 2: Add CNAME Records to your DNS

Now go to your domain provider (like GoDaddy, Cloudflare, etc.) and create two CNAME records.

Important things to check:

  • Record type must be CNAME
  • Hostnames should be: selector1._domainkey and selector2._domainkey
  • Paste the exact values from Microsoft
  • Avoid typos (this is where most DKIM setups for Office 365 fail)

DNS changes can take some time (a few minutes to a few hours, sometimes up to 48 hours).

Step 3: Enable DKIM in Microsoft 365

Once your DNS records are live:

  • Go back to the DKIM tab in the Defender portal
  • Select your domain
  • Turn on “Sign messages for this domain with DKIM signatures.

If records are correct, DKIM will be enabled instantly. If not, double-check your DNS entries.

Step 4: Verify DKIM is Working

To confirm your Office 365 DKIM setup is successful:

  • Send a test email to Gmail
  • Open the email and click Show original
  • Look for DKIM-Signature = PASS

If it passes, you’re done. Your domain is now authenticated and more secure.

DKIM Best Practices

Following configuration rules and best practices helps you get the best results from the setup:

  • Always use DKIM with SPF and DMARC: DKIM alone is not enough. Combine it with SPF and DMARC for full email authentication and better protection.
  • Enable DKIM for all custom domains: If you use multiple domains in Microsoft 365, make sure DKIM is enabled for each one, not just your primary domain.
  • Avoid making changes to signed emails: Modifying emails after they are sent (like adding footers through third-party tools) can break the DKIM signature.
  • Rotate DKIM keys periodically: For better security, update your DKIM keys from time to time to reduce the risk of misuse.
  • Monitor DKIM results regularly: Use DMARC reports or lookup tools to check if your DKIM signatures are passing consistently.
  • Keep DNS records clean and accurate: Avoid duplicate or conflicting CNAME records, as they can cause DKIM failures.
  • Use reliable verification tools: Tools like EasyDMARC DKIM Lookup help you quickly confirm if your DKIM is working correctly.
  • Act on failures quickly: If DKIM starts failing, investigate immediately. Even small DNS errors can impact your email delivery.

Ongoing DKIM Setup Maintenance

Setting up DKIM in Microsoft 365 is one of the simplest yet most powerful steps you can take to secure your email system. It protects your domain from spoofing, improves email deliverability, and builds trust with inbox providers and recipients.

Once your dkim office 365 setup is complete, do not stop there. Regularly monitor your authentication results and fix any issues quickly to maintain strong performance.

If you want to make this process even easier, EasyDMARC’s toolset can help. Use a DKIM Generator to understand your records and the DKIM Lookup tool to instantly verify if your setup is working correctly. It saves time, reduces errors, and gives you full confidence that your email authentication is in place. 

Frequently Asked Questions

Does DKIM work automatically after enabling it in Office 365?

Not immediately. DKIM starts working only after your DNS records are correctly added and detected by Microsoft 365. Even after enabling it, it may take some time before signatures appear consistently in all outgoing emails.

Can DKIM fail even if it is set up correctly?

Yes, DKIM can fail if emails are modified after being sent. This can happen due to email forwarding, third-party tools, or security gateways that change content, which breaks the DKIM signature.

Do I need separate DKIM records for subdomains?

Yes, if you send emails from subdomains, each one requires its own DKIM configuration. DKIM is domain-specific, so your main domain setup will not automatically apply to subdomains.

Is DKIM enough to stop phishing attacks completely?

No, DKIM alone cannot stop all phishing attacks. It should be used along with SPF and DMARC for better protection. Together, they help detect unauthorized emails and enforce policies against misuse

Similar Articles

image for Mailchimp DKIM setup

How to Set Up DKIM for Mailchimp

Email Spam Filtering: A Comprehensive Guide