Frontrow Technology
← Wiki

Glossary

DomainKeys Identified Mail (DKIM): Authenticating Email in Microsoft 365

DomainKeys Identified Mail (DKIM) is a cryptographic email authentication method that adds a digital signature to outgoing emails, verifying the sender's identity and ensuring message integrity.

Last reviewed 23 May 2026

What DKIM does

DKIM works by adding a digital signature to the email header. This signature is generated using a private key held by the sending organisation and verified using a corresponding public key published in the organisation’s Domain Name System (DNS) records. A selector, a unique identifier, is used to differentiate multiple DKIM keys for a single domain. The signature confirms that the message hasn’t been altered in transit and that it originates from an authorised sender, bolstering trust with recipient mail servers.

DKIM in Australian tenants today

For AU mid-market organisations utilising Exchange Online, implementing DKIM is a practical step towards demonstrating due diligence under APRA CPS 234. Enabling DKIM for both the default and any custom domains is standard practice. Microsoft 365 allows for the use of both 1024-bit and 2048-bit keys, with 2048-bit being increasingly preferred for enhanced security. Regular key rotation is crucial to minimise the impact of potential key compromise, aligning with best practices for ongoing cybersecurity resilience.

Want Frontrow to walk this through with your team?

30 minutes. No deck. We'll walk through your tenant, your priorities, and the next sensible move.