Fix Disabled DKIM Key Rotation and Missing CNAME Records in Microsoft 365
Question details
The user is unable to enable DKIM key rotation for a custom domain because the required CNAME records are missing, leaving the feature disabled.

- Product
- Microsoft 365 Exchange Online
- Device & OS
- not provided
- Scenario
- Setting up email authentication and enabling DKIM key rotation for a custom domain in Microsoft 365.
- Observed behavior
- DKIM key rotation works for the default onmicrosoft.com domain, but the rotation toggle is disabled for a custom domain, returning an error that the required CNAME record does not exist.
Ensure you have administrative access to the Microsoft 365 Defender portal and the control panel of your domain's DNS hosting provider (e.g., GoDaddy, Cloudflare, or Route 53).
Create and Verify DKIM CNAME Records in DNS
Add the specific DKIM CNAME records provided by Microsoft to your domain's DNS settings to authenticate your custom domain and enable key rotation.
Microsoft 365 requires two specific CNAME records to be published in your domain's DNS zone before DKIM can be enabled. These records point your custom domain to Microsoft's DKIM keys, allowing the system to rotate them securely.
Log in to the Microsoft 365 Defender portal, navigate to Policies & rules > Threat policies > Email authentication settings > DKIM. Select your custom domain and copy the two required CNAME hostnames and target values.
Open a new tab and sign in to the platform where your domain's DNS is managed (your domain registrar or DNS hosting provider).
Navigate to the DNS management page and create a new record. Set the type to 'CNAME', paste the first selector hostname (e.g., selector1._domainkey), and set the target to the corresponding Microsoft value.
Repeat the process to create the second CNAME record using the second selector hostname (e.g., selector2._domainkey) and its target value, then save your changes.
Wait for the DNS changes to propagate. Return to the Microsoft 365 Defender portal, refresh the DKIM page, and click the toggle to enable DKIM signatures and key rotation for your custom domain.
Simplify Your Document Workflows with WPS Office
While managing complex domain security and DNS records in Microsoft 365 requires technical expertise, your daily document creation shouldn't. WPS Office provides a free, lightweight, and user-friendly alternative to Microsoft Office for all your personal and professional tasks.

Frequently Asked Questions
Why is the DKIM rotation button disabled for my custom domain?
The DKIM rotation toggle is disabled because Microsoft 365 checks your domain's DNS for the required CNAME records before allowing configuration. If the records are missing or haven't propagated yet, the option remains locked.
Why does DKIM work on my onmicrosoft.com domain without DNS changes?
Microsoft manages the DNS infrastructure for the default onmicrosoft.com domains, meaning DKIM and the necessary CNAME records are configured automatically behind the scenes. Custom domains require you to manually prove ownership and configure routing.
How do I check if my DKIM CNAME records have propagated?
You can use online DNS lookup tools like MxToolbox. Run a 'CNAME Lookup' for your selector hostnames (e.g., selector1._domainkey.yourdomain.com) to verify if the records are resolving to the correct Microsoft target values.




