How to Find and Verify Microsoft 365 DKIM DNS Records
Question details
The user needs to locate and verify the DKIM DNS records for their Microsoft 365 domain to ensure proper email authentication setup.

- Product
- Microsoft 365
- Device & OS
- not provided
- Scenario
- Verifying domain CNAME records for DKIM authentication setup in Microsoft 365.
- Observed behavior
- Because Microsoft 365 does not store DKIM records as a recoverable archive after creation, the user must rely on DNS queries or their DNS provider to verify current values.
Ensure you have the login credentials for your domain's DNS hosting provider (such as GoDaddy) and know your exact Microsoft 365 tenant domain (e.g., yourtenant.onmicrosoft.com).
Verify DKIM Records Using the nslookup Command
Use the command-line DNS lookup tool (nslookup) to query your domain's published CNAME records without needing to log in to your DNS provider.
Since Microsoft 365 DKIM records are published as CNAME records publicly, using a DNS query is the fastest and most reliable way to verify their current values and ensure they have propagated.
Launch the Command Prompt on Windows by typing 'cmd' in the Start menu, or open Terminal on macOS.
Type the command 'nslookup -type=cname selector1._domainkey.yourdomain.com' (replacing 'yourdomain.com' with your actual domain) and press Enter.
Check the query output. It should point to a target similar to 'selector1-yourdomain-com._domainkey.yourtenant.onmicrosoft.com'.
Repeat the process by running 'nslookup -type=cname selector2._domainkey.yourdomain.com' and verify it points to the corresponding selector2 tenant address.
Once both CNAME queries return the correct onmicrosoft.com values, go to the Microsoft Defender portal and toggle the DKIM setting to 'Enable' for your domain.

Check CNAME Records Directly in Your DNS Provider
Log into your domain's DNS management portal (e.g., GoDaddy, Cloudflare) to visually confirm the DKIM records are entered correctly.
Need a Lightweight Alternative for Daily Office Tasks?
While resolving Microsoft 365 domain configuration issues can be highly technical, your everyday document work should be simple and stress-free. WPS Office provides a lightweight, highly compatible alternative to Microsoft Office, letting you create, edit, and share documents effortlessly without complex subscription management.

Frequently Asked Questions
Why can't I view my active DKIM records directly inside the Microsoft 365 admin center?
Microsoft 365 does not store DKIM records as a recoverable archive once they are generated. Because they must be published externally at your domain's DNS provider, running a DNS query is the officially recommended way to verify their current values.
What format do Microsoft 365 DKIM records use?
Microsoft 365 DKIM records are formatted as CNAME records. Typically, 'selector1._domainkey' points to 'selector1-[domain-com]._domainkey.[yourtenant].onmicrosoft.com', and the same pattern applies for 'selector2'.
How long does it take for my new DKIM records to be verifiable via nslookup?
DNS changes can take anywhere from a few minutes to 48 hours to propagate globally. If nslookup does not immediately return the correct CNAME values, wait a short while and try the query again before enabling DKIM in the Defender portal.




