A cloud-based service included in Microsoft 365, delivering scalable messaging and collaboration features with simplified management and automatic updates.
The AI-generated answer provides helpful information and correctly explains that Microsoft 365 may sign mail with the *.onmicrosoft.com domain if DKIM is not enabled for the custom domain. It also provides appropriate guidance to verify the DKIM configuration using Get-DkimSigningConfig.
However, I would suggest a minor adjustment: while a DKIM-Signature of d=example.onmicrosoft.com can be expected when custom-domain DKIM is not enabled, the documentation does not specifically explain why ARC-Authentication-Results shows dkim=pass header.d=example.com while the visible DKIM signature uses example.onmicrosoft.com. Therefore, reviewing the complete message headers and confirming the DKIM configuration for example.com would be recommended before drawing a final conclusion.
Please try running the PowerShell to verify the status:
Get-DkimSigningConfig | Format-List Name,Enabled,Status,Selector1CNAME,Selector2CNAME