Your Microsoft email will likely still work after April 2026 even if you don’t send over 5,000 emails a day, but implementing DMARC, SPF, and DKIM is highly recommended to prevent future deliverability issues. Microsoft began routing messages from high-volume (5,000+ emails/day) non-compliant domains to junk folders on May 5, 2025, with plans to reject them at a future, unannounced date. While not immediately required, these authentication measures are best practices that improve deliverability and protect your domain from spam and spoofing.
Use this quick domain scanner tool >>
Step-by-step Guide to add DKIM to a Microsoft 365 account
To get your DKIM record for a Microsoft account, sign in to the Microsoft 365 Defender portal (security.microsoft.com), navigate to the DKIM settings, and enable DKIM for your domain. Microsoft will then provide two CNAME or TXT records. You must log in to your domain’s DNS provider (e.g., GoDaddy, Cloudflare), create the specified DNS records using the provided values, and then return to the Defender portal to enable DKIM for that domain.
- Sign in to the Microsoft 365 Defender Portal
- Go to
https://security.microsoft.com/dkimv2or search for “DKIM” in the Microsoft 365 admin center to find the DKIM settings page. - Sign in with your Microsoft 365 email address and password.
- Go to
- Generate the DKIM Records
- On the DKIM settings page, select the domain you want to configure.
- If DKIM is not already set up for the domain, you will see an option to “create DKIM keys” or “enable DKIM”.
- Clicking this will generate the DKIM records for your domain. These are typically two CNAME records (or sometimes TXT records) and will have a specific host/name (e.g.,
selector1._domainkey) and a value.
- Add the Records to Your DNS Provider
- Open a new browser tab and log in to your DNS hosting provider’s account (e.g., GoDaddy, Cloudflare, or your domain registrar).
- Navigate to the section for managing DNS records.
- Create two new DNS records, specifying the record type as CNAME (or TXT, depending on what Microsoft provided).
- Copy the host/name and the value/target from the DKIM records provided by Microsoft into the corresponding fields in your DNS provider’s interface.
- Save the changes to your DNS records.
- Enable DKIM in Microsoft 365
- Return to the Microsoft 365 Defender Portal.
- Select your domain again and turn on the “enable” button for DKIM.
- It may take a few minutes to a couple of days for the DNS changes to propagate and for the status to update.
- Verify the DKIM Record (Optional)
- After enabling DKIM and waiting for propagation, you can use a DNS lookup tool to check if your DKIM record is active and correctly published


