Configure email DNS and find the selector
-
1
Open DKIM authentication
In the Microsoft Defender portal open Email authentication settings and the DKIM tab, then select the custom sender domain.
-
2
Copy both required CNAME values
Use the exact selector1 and selector2 CNAME targets shown for your tenant. Do not construct them from an old example because Microsoft uses tenant-specific and newer dynamic record formats.
-
3
Publish and enable
Add both CNAME records at the authoritative DNS provider, wait until Microsoft detects them, then enable signing for the custom domain.
-
4
Find the active selector
Microsoft keeps selector1 and selector2 for key rotation but signs with one at a time. Send a new external message and read s= in the DKIM-Signature whose d= value matches the custom domain.
-
5
Validate with VerifySeal
Enter the active selector shown in the message header and run the email DNS check. Keep both CNAME records published for future Microsoft key rotation.