Microsoft 365 uses two selectors by default: selector1 and selector2, both published as CNAMEs pointing to selector1-yourdomain-com._domainkey.tenantid.onmicrosoft.com. Microsoft rotates keys between them automatically. Enable DKIM in Microsoft 365 Defender → Email & Collaboration → Policies → DKIM, select your domain, and publish the two CNAME records shown. Look up the active selector on any domain with the DKIM lookup tool. The tool tries common selector names automatically.
All questions
How do I find the DKIM selector for Microsoft 365?
Read the full guide
What Is DKIM?
DKIM attaches a cryptographic signature to every email you send. Receiving servers verify the signature against a public key in your DNS — proving the message is authentic and untampered. No DKIM means anyone can forge your brand's email.