Hitronics you can leave the tenantname.mail.onmicrosoft.com in the send connector. This is because we don't support DNSSEC for onmicrosoft.com domains, so that tenantname.mail.onmicrosoft.com domain name is never going to change. If you want to enable DNSSEC for contoso.com then you'll need to change the send connector hostname to contoso-com.a-v1.mx.microsoft after enabling DNSSEC. If you are changing the send connector hostname, then change it immediately after enabling DNSSEC and receiving your new "contoso-com.a-v1.mx.microsoft" domain name. During public preview, you will be able to fall back to the contoso-com.mail.protection.outlook.com but once the feature reaches GA the contoso-com.mail.protection.outlook.com record will be deleted approximately 48 hours after DNSSEC enablement.
There was a brief issue with provisioning DNSSEC records on our side yesterday, it's working now as michaelkennedy mentioned.