
If your business sends invoices, quotes, or client updates by email, there’s a good chance someone could send a fake version of that email — one that looks like it came from you, but didn’t. That’s called email spoofing, and it’s one of the most common ways criminals steal money and trust from small and medium-sized businesses.
DKIM (DomainKeys Identified Mail) is one of the simplest, most effective tools for stopping this. It’s free, it takes minutes to switch on in Microsoft 365, and most business owners have never heard of it. This post explains what DKIM actually does, why it matters more than ever, and exactly how to get it working if your business runs on Microsoft 365.
What is DKIM, in plain English?
Every email you send from Microsoft 365 can carry a hidden digital signature — a bit like a wax seal on an old letter. That signature is created using a private cryptographic key that only your mail server holds. When the email arrives at the recipient’s inbox, their email provider checks that signature against a public key published in your domain’s DNS records.
If the signature checks out, the receiving mail server knows two things: the email genuinely came from your domain, and nothing in it was altered in transit. If the signature is missing, broken, or doesn’t match, that’s a red flag — and increasingly, it’s a reason for the email to be sent straight to spam or blocked outright.
That’s DKIM in a nutshell: proof that an email claiming to be from your business actually is.
Why DKIM matters for your business
It stops criminals impersonating you. Without DKIM (and its companion protocols SPF and DMARC), there’s very little technically stopping someone from sending an email that appears to come from “accounts@yourbusiness.com.au.” This is exactly how a lot of invoice fraud and business email compromise scams work — a criminal sends a convincing fake email to one of your clients or suppliers, asking them to pay an invoice into a different bank account. When it works, the financial and reputational damage falls on the business being impersonated, not the criminal.
It protects your deliverability. Mailbox providers like Gmail, Outlook.com, and Yahoo have become far stricter about which emails they’ll actually deliver to the inbox versus quietly filing into spam or rejecting outright. Since 2024, Google and Yahoo have required proper email authentication (SPF, DKIM, and DMARC) for anyone sending meaningful volumes of email to their users, and enforcement has only tightened since. If your domain isn’t authenticated, your marketing emails, invoices, and even one-to-one messages are increasingly likely to land in spam — or never arrive at all.
It builds trust automatically, in the background. Unlike a lot of security measures, DKIM is invisible to your customers when it’s working. There’s no extra step for them, no pop-up, nothing to click. It just quietly increases the odds that your genuine emails are trusted and delivered, while making it harder for anyone impersonating you to succeed.
It’s part of a bigger picture. DKIM doesn’t work alone — it’s one leg of a three-part system alongside SPF (which authorises which servers can send mail for your domain) and DMARC (which tells receiving servers what to do if SPF or DKIM checks fail, and reports back to you when someone tries to spoof your domain). Setting up DKIM properly is a prerequisite for a strong DMARC policy, which is where the real protection against domain impersonation kicks in.
Why this specifically needs setting up in Microsoft 365
Here’s the part that catches a lot of business owners out: Microsoft 365 does not fully protect your custom domain by default.
If you’re sending email from your own domain (e.g., yourbusiness.com.au) rather than the default *.onmicrosoft.com address, Microsoft 365 does not automatically sign your outgoing mail with DKIM for that custom domain. Signing only happens automatically for the default onmicrosoft.com domain — which almost no real business actually sends mail from. In other words, the domain your clients actually see in their inbox is very likely unprotected until someone deliberately switches DKIM on.
This is a common gap even in businesses that consider themselves fairly security-conscious. Microsoft 365 has been configured, mailboxes work fine, email flows normally — but nobody has gone into the admin settings and specifically enabled DKIM signing for the custom domain. Everything looks fine day to day, right up until someone spoofs the domain or a major inbox provider starts silently filtering the business’s emails.
The bottom line
DKIM is a small, largely invisible change with an outsized payoff: it makes it dramatically harder for criminals to impersonate your business by email, and it keeps your legitimate emails landing where they’re supposed to — in the inbox, not spam. For any business running Microsoft 365 on its own domain, it’s one of the highest-value, lowest-effort security improvements available, and — paired with SPF and DMARC — it forms the foundation of a properly protected email domain.
If you’re not sure whether DKIM is switched on for your domain, or you’d like it (along with SPF and DMARC) set up correctly and verified, get in touch with M1 IT Systems. We can check your current email authentication status and get it sorted properly, so your business is protected and your emails are getting delivered.
Sources referenced for this article:
How to use DKIM for email in your custom domain – Microsoft Learn
Email Security Best Practices in 2026 – EasyDMARC
The Complete DMARC Best Practices Guide for 2026 – EasyDMARC
Google and Yahoo Email Authentication Requirements 2026 – PowerDMARC
Office 365 DKIM Setup: Quick Guide with CNAME Examples – MailReach
About The Author: Rory McElwee
More posts by Rory McElwee