A cloud-based service included in Microsoft 365, delivering scalable messaging and collaboration features with simplified management and automatic updates.
Yes, this is expected if DKIM signing for the custom domain is not enabled and Microsoft 365 is signing with the tenant’s *.onmicrosoft.com domain instead.
Key points:
-
*.onmicrosoft.comis signed by default- Microsoft 365 signs outbound mail for the initial
*.onmicrosoft.comdomain by default. - No public DNS DKIM CNAME records are required for that Microsoft-managed domain.
- Microsoft 365 signs outbound mail for the initial
- Custom domains require separate DKIM configuration
- For a custom domain such as
example.com, DKIM signing needs to be enabled for that domain. - This requires publishing the two DKIM CNAME records for the custom domain and then enabling DKIM signing.
- To verify the current state, run:
Get-DkimSigningConfig | Format-List Name,Enabled,Status,Selector1CNAME,Selector2CNAME - If the custom domain shows
Enabled: FalseandStatus: NoDKIMKeysorCnameMissing, create the required CNAME records and then enable DKIM:Set-DkimSigningConfig -Identity example.com -Enabled $true
- For a custom domain such as
- DMARC alignment requires DKIM for the From domain
- Microsoft’s guidance for combined authentication failures is to enable DKIM signing for the From address domain because DKIM alignment provides the aligned pass that DMARC needs.
- If mail is signed only with
example.onmicrosoft.com, that DKIM domain does not align withFrom: [email protected].
- Why ARC can show
dkim=pass header.d=example.com- ARC preserves authentication results.
- The provided context supports ARC as a mechanism that preserves authentication results through message modification, but it does not document a case where ARC reports
header.d=example.comwhile the visible outboundDKIM-Signatureisd=example.onmicrosoft.com. - The supported conclusion is that the actual DKIM signature used for downstream DMARC evaluation is the one in the message headers. If that signature is
d=example.onmicrosoft.com, then custom-domain DKIM forexample.comshould be checked and enabled if the goal is aligned DKIM forexample.com.
- What to do next
- In Exchange Online PowerShell, check whether
example.comappears inGet-DkimSigningConfig. - If needed, retrieve the exact
Selector1CNAMEandSelector2CNAMEvalues forexample.com. - Publish those two CNAME records in DNS for
example.com. - After DNS propagation, enable DKIM for
example.com:Set-DkimSigningConfig -Identity example.com -Enabled $true - Send a test message to an external mailbox and inspect headers:
- Confirm a
DKIM-Signatureheader exists. - Confirm
d=example.com. - Confirm
Authentication-ResultsincludesDKIM=passorDKIM=OK.
- Confirm a
- In Exchange Online PowerShell, check whether
If sender and recipient are in the same domain, or in different domains controlled by the same organization, Microsoft 365 can omit the DKIM signature entirely, so testing should be done by sending to an external mailbox in another email system.