Microsoft 365 uses two DKIM selector CNAME records to authenticate mail sent from a custom domain. If NicNames Free Name-Servers host your DNS, this guide shows where to place Microsoft’s exact values, how to check the records, and when to enable DKIM signing.
Before you add the records
Sign in as an administrator for the Microsoft 365 tenant that sends mail from your domain. The custom domain must already be added to Microsoft 365. In Microsoft Defender, open the DKIM tab under Email authentication settings, select the domain, and if the status is NoDKIMKeys, try enabling DKIM once to generate the keys. After the CnameMissing status appears, open the domain details and copy both names and targets from “Publish CNAMEs”. Microsoft assigns part of each target for your tenant, so do not build the target from an example or copy one from another domain.
Check who hosts your domain’s authoritative DNS. In your NicNames account, open Domains → ClassicDNS, select the domain’s Settings, and review Name-Servers. Continue in NicNames only if Free Name-Servers are in use. With Custom Name-Servers, make the records at the DNS provider serving those nameservers instead. Keep your existing MX and website records in place.
Add the two selector CNAME records
- From the domain’s Settings page, open DNS Records → Manage and select + Add record.
- Choose CNAME. In Name, enter the first selector name supplied by Microsoft, usually selector1._domainkey. In Host alias, paste that selector’s exact Microsoft CNAME target.
- Repeat for the second selector, usually selector2._domainkey, with its own exact target. Check that neither name already has a conflicting record before saving. Microsoft 365 calls for two CNAMEs, not DKIM-key TXT records.
- Review the TTL and select Save. Microsoft recommends at least 3,600 seconds for these CNAMEs; the value shown in NicNames may already meet that minimum.
Confirm signing
Check that public DNS returns both selector CNAMEs with the targets shown in Microsoft Defender. DNS caches can delay what different resolvers display; if a record seems missing, first confirm that you edited the authoritative provider and compare the exact Name and Host alias. Our DNS change troubleshooting guide explains those checks.
Once Microsoft detects the records, return to the domain’s DKIM details in Defender and enable Sign messages for this domain with DKIM signatures. The expected status is Signing DKIM signatures for this domain. Send a test message from the domain and inspect its authentication results to confirm DKIM passes; DNS records alone do not show that signing is active.
Keep the rest of email authentication in view
DKIM is one part of email authentication. Review SPF and DMARC for every service that sends as your domain. For a separate SPF review example, see our Google Workspace SPF checklist; use your own provider’s values, not Google’s, for Microsoft 365. If you are unsure which nameservers or records are active, contact NicNames support before replacing an existing DNS record.


