Provider
Microsoft 365 DKIM selectors
A miss is not proof
DKIM selectors cannot be listed through DNS. If none of the selectors below answers on a domain, that does not prove the domain has no DKIM or does not use Microsoft 365: the selector may be custom, rotated or retired. A signed message shows the real one.
Microsoft 365 (Exchange Online) signs mail from a custom domain with selector1 and selector2. The host names are the same in every organisation: two CNAME records on your domain that point at keys Microsoft publishes.
Custom domains added since Microsoft introduced its updated record format in May 2025 point under <prefix>.<partition>-v1.dkim.mail.microsoft. Older custom domains keep the format under <prefix>.onmicrosoft.com, where the prefix is the first label of the tenant’s initial onmicrosoft.com domain. Microsoft assigns the partition character (its examples are r and n). The two formats cannot coexist for the same selector.
Microsoft calls the values in its article illustrative. The real targets are in the Defender portal, or in Selector1CNAME and Selector2CNAME from Get-DkimSigningConfig. dkim.fyi follows the CNAME and attributes it to Microsoft when the target ends in onmicrosoft.com or dkim.mail.microsoft. Its discovery tries this pair first when the MX or SPF record points at protection.outlook.com.
Only one selector signs at a time. The other waits for a key rotation, which takes four days (96 hours), and no second rotation can start meanwhile. New-DkimSigningConfig creates 1024-bit keys unless KeySize is 2048, and a later change to 2048 reaches one selector per rotation.
Mail from the initial onmicrosoft.com domain is signed automatically, and Microsoft says that domain currently has no automatic key rotation.
- Usual selector
selector1andselector2, both published- Record type
- CNAME
- Dataset confidence
- highHow sure the dataset is that Microsoft 365 uses these names, not that a key found under one is theirs.
Selectors
| Selector | Source | Status | Note |
|---|---|---|---|
selector1 | Vendor documentation | current | One of the pair. Only one of the two is active at a time. |
selector2 | Vendor documentation | current | The other half. Rotation fails later without its CNAME. |
Record forms
| Name | Type | Value | Note |
|---|---|---|---|
selector1._domainkey.<domain> | CNAME | selector1-<domain-with-dashes>._domainkey.<prefix>.<partition>-v1.dkim.mail.microsoft | Domains added since May 2025. Older: selector1-<domain-with-dashes>._domainkey.<prefix>.onmicrosoft.com |
selector2._domainkey.<domain> | CNAME | selector2-<domain-with-dashes>._domainkey.<prefix>.<partition>-v1.dkim.mail.microsoft | Domains added since May 2025. Older: selector2-<domain-with-dashes>._domainkey.<prefix>.onmicrosoft.com |
Where sources disagree
- Rotation: one section of Microsoft’s article says an admin starts key rotation and that the onmicrosoft.com domain has no automatic rotation; the troubleshooting section says Microsoft 365 rotates keys automatically. No interval is given.
- The selector in a signature: the prose gives
s=selector1-contoso-comas an example, but the sample DKIM-Signature header on the same page showss=selector1.
Check it live
What goes wrong
- Only the selector1 CNAME is published
- Signing can be turned on with one record in place. Key rotation then fails, because the selector2 CNAME is missing.
- Host name with the domain twice, or without _domainkey
- The DKIM toggle in the Defender portal does not enable and the status stays
CnameMissing. - A TXT record instead of a CNAME
- A TXT record holding the key means managing keys and rotation by hand, which Microsoft says is not supported for Microsoft 365.
- A target that does not match the domain
- The target contains the domain with dashes and the tenant prefix, so a value copied from another domain or an example is wrong. Microsoft also lists a TTL set too low and trailing dot problems. When
Set-DkimSigningConfigcannot find the CNAMEs, its error gives the values to publish. - Taking any selector1 record as Microsoft 365
selector1andselector2are also on dkim.fyi’s list of generic selectors. A record under either name is Microsoft 365 only when its CNAME target has one of the two Microsoft formats.- A CNAME whose target does not exist
- dkim.fyi reports the CNAME target as missing. Compare it with the value Microsoft gives for that domain and selector.