How to Fix Microsoft 365 Cannot Enable DKIM for Custom Domain
Question details
Users are unable to enable DKIM for a custom domain in Microsoft 365 despite properly configuring the required CNAME records in their DNS settings.

- Product
- Microsoft 365
- Device & OS
- not provided
- Scenario
- Configuring domain security and email authentication protocols (DKIM/DMARC) for a custom domain.
- Observed behavior
- DKIM functions normally for the default onmicrosoft.com domain, but custom domain messages are signed with onmicrosoft.com. This triggers DMARC warnings because Microsoft 365 fails to detect the existing custom domain CNAME records.
Ensure that you have access to your DNS hosting provider's control panel and possess global administrator privileges in the Microsoft 365 Admin Center. Please note that DNS changes can take up to 48 hours to fully propagate.
Verify CNAME Records and Open a Microsoft 365 Support Ticket
Since this is often a backend synchronization issue, validating your DNS records and escalating the issue to Microsoft Support is the most effective resolution.
Before escalating to support, it is crucial to ensure that your DNS provider has fully propagated the CNAME records generated by Microsoft 365.
If the records are perfectly matched to the generated values but remain undetected by the portal, the issue lies within Microsoft's backend validation systems and requires engineering intervention.
Log in to your DNS hosting provider's admin panel. Verify that the two CNAME selector records (e.g., selector1._domainkey and selector2._domainkey) exactly match the target hostnames and subdomain structures provided by Microsoft 365.
Log into the Microsoft 365 Admin Center using your global administrator credentials. Navigate to the left sidebar menu and click on 'Support', then select 'Help & support'.
Click 'New service request' and provide a detailed description of the problem. Explicitly state that the custom domain CNAME records match the onmicrosoft.com configuration but are failing validation, and request a backend investigation.

Looking for a Lightweight Alternative to Microsoft Office?
While domain administration and DKIM settings require Microsoft 365's backend, your daily document tasks do not have to be tied to expensive subscriptions. WPS Office provides a powerful, free, lightweight, and highly compatible alternative for creating, editing, and managing your documents, spreadsheets, and presentations with a familiar UI and seamless migration.
- 1. Download the Installer: Visit the official WPS Office website and click the download button for your specific operating system (Windows, Mac, or Linux).
- 2. Install WPS Office: Run the downloaded installation file and follow the on-screen prompts to quickly set up the application.
- 3. Start Creating: Launch WPS Office and immediately start opening your existing Microsoft Office files without any need for format conversion.

Frequently Asked Questions
Why is Microsoft 365 signing my emails with onmicrosoft.com instead of my custom domain?
When Microsoft 365 fails to verify the DKIM CNAME records for your custom domain, it falls back to signing outbound emails using the default tenant domain (onmicrosoft.com). This is done to ensure the emails are authenticated and not completely rejected by recipient spam filters.
How long does DKIM DNS propagation usually take?
DNS changes typically take anywhere from 15 minutes to 48 hours to fully propagate across global internet servers. If the Microsoft 365 Defender portal still cannot detect your CNAME records after 48 hours, it is likely a backend synchronization glitch requiring support intervention.
Will my DMARC fail if my DKIM uses the default Microsoft domain?
Yes. DMARC requires strict or relaxed alignment between the 'From' domain in the email header and the domain used in the DKIM signature. If your email is sent from your custom domain but signed by onmicrosoft.com, it will trigger an alignment failure and generate DMARC warnings.
Are DKIM selector records identical for every domain?
While the prefix structure is similar (e.g., selector1._domainkey), the specific target values generated by Microsoft 365 are completely unique to each individual domain. You must use the exact target strings provided in the portal specifically for your custom domain.




