DKIM in M365 - Mydomain.com vs Mydomain.onmicrosoft.com

Laurie Stearn 151 Reputation points
2026-09-24T17:56:38.9433333+00:00

Google reveals the title is taken from a Spiceworks thread.

The question relates to an o365info article "Add DKIM and DMARC for onmicrosoft.com domain in Microsoft 365".

Performing this in M365 will generate another set of DKIM CNAME selector1._domainkey and selector2._domainkey keys. There's a discussion in Stack Exchange "How to handle duplicate DKIM selectors?" which suggests that key duplication is legal for TXT records.

Does that now apply to CNAME or is the answer given in Spiceworks correct - in that all handling of Mydomain.onmicrosoft.com is handled internally and is not required (as is suggested in the o365info article)?

Exchange Online
Exchange Online

A cloud-based service included in Microsoft 365, delivering scalable messaging and collaboration features with simplified management and automatic updates.

0 comments No comments

Answer accepted by question author
Ivory 1,825 Reputation points Independent Advisor
2026-09-24T18:44:47.27+00:00

Hi Laurie,

For the default <tenant>.onmicrosoft.com domain, no additional public DNS DKIM CNAME records are required. Microsoft automatically handles DKIM signing for the onmicrosoft.com domain and manages the associated keys internally.

The selector1._domainkey and selector2._domainkey CNAME records are only required when enabling DKIM for a custom domain (for example, mydomain.com). These records are published in the DNS zone of the custom domain and do not apply to the Microsoft-managed onmicrosoft.com domain.

Therefore, the duplicate-selector concern discussed for DKIM records is not applicable to the Microsoft-managed onmicrosoft.com domain.

For more information, please consult How to use DKIM for email in your custom domain - Microsoft Defender for Office 365 | Microsoft Lea…

If you have any questions or need further assistance, please feel free to share them in the comments on this post.


If the answer is helpful, please click 'Yes' and kindly upvote it.

Note: Please follow the steps in the forum documentation to enable e-mail notifications if you want to receive the related email notification for this thread. 

Was this answer helpful?

1 person found this answer helpful.

1 additional answer

Sort by: Most helpful
  1. AI answer

    2026-09-24T17:56:54.9133333+00:00

    No extra public DNS CNAME records are required for the initial mydomain.onmicrosoft.com domain.

    In Microsoft 365, outbound mail from senders in the initial *.onmicrosoft.com domain is automatically DKIM signed by that *.onmicrosoft.com domain by default. For custom domains such as mydomain.com, DKIM signing does not occur until DKIM is configured for that custom domain.

    For a custom domain, Microsoft 365 requires two DNS CNAME records:

    • selector1._domainkey
    • selector2._domainkey

    Those records are created in the DNS zone of the custom domain, using the selector values returned by Get-DkimSigningConfig.

    For the *.onmicrosoft.com domain, the documentation states to go directly to the next step instead of creating CNAME records at a registrar. That means Microsoft handles the onmicrosoft.com domain internally, and the duplicate-selector concern does not apply in public DNS for that domain.

    If DKIM is being configured for both mydomain.com and mydomain.onmicrosoft.com, the custom domain gets its own public DNS CNAME pair, while the onmicrosoft.com domain does not require a separate public DNS pair.


    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.