logo
search
Security Policy Errors

How to Find and Verify Microsoft 365 DKIM DNS Records

Partner EditorPartner Editor Oct 7, 2026 869 views

Question details

The user needs to locate and verify the DKIM DNS records for their Microsoft 365 domain to ensure proper email authentication setup.

How to Find and Verify Microsoft 365 DKIM DNS Records
Product
Microsoft 365
Device & OS
not provided
Scenario
Verifying domain CNAME records for DKIM authentication setup in Microsoft 365.
Observed behavior
Because Microsoft 365 does not store DKIM records as a recoverable archive after creation, the user must rely on DNS queries or their DNS provider to verify current values.
Before you start

Ensure you have the login credentials for your domain's DNS hosting provider (such as GoDaddy) and know your exact Microsoft 365 tenant domain (e.g., yourtenant.onmicrosoft.com).

Solution 1Recommended

Verify DKIM Records Using the nslookup Command

Use the command-line DNS lookup tool (nslookup) to query your domain's published CNAME records without needing to log in to your DNS provider.

Since Microsoft 365 DKIM records are published as CNAME records publicly, using a DNS query is the fastest and most reliable way to verify their current values and ensure they have propagated.

1
Open Command Prompt or Terminal

Launch the Command Prompt on Windows by typing 'cmd' in the Start menu, or open Terminal on macOS.

2
Query the first DKIM selector

Type the command 'nslookup -type=cname selector1._domainkey.yourdomain.com' (replacing 'yourdomain.com' with your actual domain) and press Enter.

3
Verify the CNAME destination

Check the query output. It should point to a target similar to 'selector1-yourdomain-com._domainkey.yourtenant.onmicrosoft.com'.

4
Query the second DKIM selector

Repeat the process by running 'nslookup -type=cname selector2._domainkey.yourdomain.com' and verify it points to the corresponding selector2 tenant address.

5
Enable DKIM in Defender

Once both CNAME queries return the correct onmicrosoft.com values, go to the Microsoft Defender portal and toggle the DKIM setting to 'Enable' for your domain.

Verify DKIM Records Using the nslookup Command
Verification Successful: If the nslookup command returns the correct target records, your DNS setup is complete and ready for Microsoft 365 DKIM activation.
Free Microsoft Office alternative

Need a Lightweight Alternative for Daily Office Tasks?

While resolving Microsoft 365 domain configuration issues can be highly technical, your everyday document work should be simple and stress-free. WPS Office provides a lightweight, highly compatible alternative to Microsoft Office, letting you create, edit, and share documents effortlessly without complex subscription management.

Fully compatible with Microsoft Office formats including DOCX, XLSX, and PPTX.Lightweight architecture ensures quick installation and smooth performance on older devices.Familiar user interface requiring zero learning curve for users switching from Microsoft Office.Built-in advanced PDF editing tools completely free of charge.
microsoft office alternative - wps office

Frequently Asked Questions

Why can't I view my active DKIM records directly inside the Microsoft 365 admin center?

Microsoft 365 does not store DKIM records as a recoverable archive once they are generated. Because they must be published externally at your domain's DNS provider, running a DNS query is the officially recommended way to verify their current values.

What format do Microsoft 365 DKIM records use?

Microsoft 365 DKIM records are formatted as CNAME records. Typically, 'selector1._domainkey' points to 'selector1-[domain-com]._domainkey.[yourtenant].onmicrosoft.com', and the same pattern applies for 'selector2'.

How long does it take for my new DKIM records to be verifiable via nslookup?

DNS changes can take anywhere from a few minutes to 48 hours to propagate globally. If nslookup does not immediately return the correct CNAME values, wait a short while and try the query again before enabling DKIM in the Defender portal.