logo
search
Security Policy Errors

Fix Disabled DKIM Key Rotation and Missing CNAME Records in Microsoft 365

Steve KSteve K Sep 28, 2026 870 views

Question details

The user is unable to enable DKIM key rotation for a custom domain because the required CNAME records are missing, leaving the feature disabled.

How to Fix Disabled DKIM Key Rotation and Missing CNAME Records
Product
Microsoft 365 Exchange Online
Device & OS
not provided
Scenario
Setting up email authentication and enabling DKIM key rotation for a custom domain in Microsoft 365.
Observed behavior
DKIM key rotation works for the default onmicrosoft.com domain, but the rotation toggle is disabled for a custom domain, returning an error that the required CNAME record does not exist.
Before you start

Ensure you have administrative access to the Microsoft 365 Defender portal and the control panel of your domain's DNS hosting provider (e.g., GoDaddy, Cloudflare, or Route 53).

Solution 1Recommended

Create and Verify DKIM CNAME Records in DNS

Add the specific DKIM CNAME records provided by Microsoft to your domain's DNS settings to authenticate your custom domain and enable key rotation.

Microsoft 365 requires two specific CNAME records to be published in your domain's DNS zone before DKIM can be enabled. These records point your custom domain to Microsoft's DKIM keys, allowing the system to rotate them securely.

1
Obtain CNAME values from Microsoft 365

Log in to the Microsoft 365 Defender portal, navigate to Policies & rules > Threat policies > Email authentication settings > DKIM. Select your custom domain and copy the two required CNAME hostnames and target values.

2
Log in to your DNS provider

Open a new tab and sign in to the platform where your domain's DNS is managed (your domain registrar or DNS hosting provider).

3
Add the first CNAME record

Navigate to the DNS management page and create a new record. Set the type to 'CNAME', paste the first selector hostname (e.g., selector1._domainkey), and set the target to the corresponding Microsoft value.

4
Add the second CNAME record

Repeat the process to create the second CNAME record using the second selector hostname (e.g., selector2._domainkey) and its target value, then save your changes.

5
Enable DKIM rotation

Wait for the DNS changes to propagate. Return to the Microsoft 365 Defender portal, refresh the DKIM page, and click the toggle to enable DKIM signatures and key rotation for your custom domain.

Allow Time for DNS Propagation: DNS changes are not instantaneous. If enabling DKIM fails immediately after adding the records, wait 1 to 2 hours (up to 48 hours depending on your TTL settings) and try again.
Free Microsoft Office alternative

Simplify Your Document Workflows with WPS Office

While managing complex domain security and DNS records in Microsoft 365 requires technical expertise, your daily document creation shouldn't. WPS Office provides a free, lightweight, and user-friendly alternative to Microsoft Office for all your personal and professional tasks.

Fully compatible with Microsoft Word, Excel, and PowerPoint formats (.docx, .xlsx, .pptx)Familiar tabbed interface ensuring a seamless migration with zero learning curveLightweight application that runs smoothly on Windows, Mac, Linux, and mobile devicesBuilt-in PDF editing, merging, and conversion tools included for free
microsoft office alternative - wps office

Frequently Asked Questions

Why is the DKIM rotation button disabled for my custom domain?

The DKIM rotation toggle is disabled because Microsoft 365 checks your domain's DNS for the required CNAME records before allowing configuration. If the records are missing or haven't propagated yet, the option remains locked.

Why does DKIM work on my onmicrosoft.com domain without DNS changes?

Microsoft manages the DNS infrastructure for the default onmicrosoft.com domains, meaning DKIM and the necessary CNAME records are configured automatically behind the scenes. Custom domains require you to manually prove ownership and configure routing.

How do I check if my DKIM CNAME records have propagated?

You can use online DNS lookup tools like MxToolbox. Run a 'CNAME Lookup' for your selector hostnames (e.g., selector1._domainkey.yourdomain.com) to verify if the records are resolving to the correct Microsoft target values.