logo
search
Security Policy Errors

How to Fix Cannot Enable DKIM for a Custom Domain in Microsoft 365

Olivia MillerOlivia Miller Oct 1, 2026 869 views

Question details

The user is unable to enable DKIM for a custom domain because Microsoft 365 cannot detect the required CNAME records.

How to Fix 'Cannot Enable DKIM for a Custom Domain' in Microsoft 365
Product
Microsoft 365
Device & OS
not provided
Scenario
Configuring email security and authentication by enabling DKIM for a custom domain in the Microsoft 365 admin center.
Observed behavior
The system throws an error stating that the DKIM CNAME records cannot be detected, preventing the user from successfully enabling DKIM.
Before you start

Log in to your domain registrar's DNS management console and have the Microsoft 365 DKIM setup documentation ready for reference.

Solution 1Recommended

Verify CNAME Records and Allow DNS Propagation

Ensure your DKIM CNAME records match Microsoft's requirements exactly and allow sufficient time for global DNS propagation.

Microsoft 365 requires two specific CNAME records to enable DKIM. Even a minor typo, an invisible space, or an unpropagated DNS change will cause detection failures.

1
Compare Records

Open your DNS management portal and compare the two DKIM CNAME records you created against Microsoft's documentation character by character.

2
Remove Hidden Characters

Check for and delete any hidden characters, trailing spaces, or unnecessary punctuation in both the host name and destination fields.

3
Perform an External DNS Lookup

Use an external DNS lookup tool (such as MxToolbox) to query your domain's CNAME records and confirm they are publicly visible.

4
Wait for Propagation

Allow up to 24 hours or longer for the DNS changes to fully propagate across all global servers.

5
Retry Enabling DKIM

Return to the Microsoft 365 Defender portal, navigate to the DKIM settings, and attempt to enable DKIM again.

Verify CNAME Records and Allow DNS Propagation
DNS Propagation Times: While some DNS changes take effect in minutes, standard propagation can take anywhere from 24 to 48 hours depending on your DNS provider's TTL (Time to Live) settings.
Free Microsoft Office alternative

Need a simpler office suite? Try WPS Office

While you manage complex domain configurations and Exchange settings in Microsoft 365, you might also want a hassle-free, lightweight solution for your daily document tasks. WPS Office is a powerful, free alternative that offers seamless compatibility with Word, Excel, and PowerPoint files without the administrative overhead.

  1. 1. Download the Installer: Visit the official WPS website and click on the 'Download WPS Office Free' button.
  2. 2. Install WPS Office: Run the downloaded installer and follow the simple on-screen instructions.
  3. 3. Open Your Documents: Launch WPS Office to easily open, edit, and save your existing Microsoft Office files.
Fully compatible with Microsoft Office formats (.docx, .xlsx, .pptx).Free and lightweight alternative to heavy enterprise office applications.Familiar tabbed user interface for an easy transition.All-in-one suite combining documents, spreadsheets, presentations, and PDFs.
microsoft office alternative - wps office

Frequently Asked Questions

How long does it take for DKIM DNS records to propagate?

DNS propagation typically takes anywhere from a few minutes to 24 hours. In some rare cases, depending on your domain registrar and TTL settings, it may take up to 48 hours for the new CNAME records to be fully detectable by Microsoft 365.

What are common formatting mistakes when adding DKIM CNAME records?

The most common mistakes include accidentally copying blank spaces at the beginning or end of the string, missing the trailing dot (if required by your DNS host), or pasting the entire destination URL into the hostname field.

How can I check if my DKIM CNAME records are publicly visible?

You can use free third-party DNS lookup tools like MxToolbox or Google Admin Toolbox. Simply select the 'CNAME Lookup' option and enter the specific DKIM selector hostname (e.g., selector1._domainkey.yourdomain.com) to see if it resolves to the correct Microsoft destination.