How to Fix Microsoft 365 DKIM Error Retrieving Encrypted Key
Question details
The user is encountering an 'Error in retrieving encrypted key' message when attempting to configure DKIM for a Microsoft 365 domain.

- Product
- Microsoft 365
- Device & OS
- not provided
- Scenario
- Setting up DKIM signatures for custom domains or the default onmicrosoft.com domain using the Microsoft Defender portal.
- Observed behavior
- The DKIM setup fails with an encrypted key retrieval error, even after successful domain verification and valid DNS checks.
Ensure you have global administrator or Exchange administrator privileges in Microsoft 365, and verify that your domain's DNS CNAME records have had at least 24 to 48 hours to fully propagate.
Verify DNS CNAME Records and Re-enable DKIM
Confirm that the correct DKIM CNAME records are published and fully propagated before attempting to enable DKIM in the Defender portal.
Microsoft 365 relies on correctly propagated CNAME records to generate and retrieve DKIM keys. If your domain's DNS is not fully propagated across global servers, the Microsoft Defender portal may return encrypted-key errors during the activation process.
Log in to your DNS hosting provider's control panel and verify that the two DKIM CNAME records provided by Microsoft are properly published for your custom domain.
Allow up to 48 hours for full DNS propagation. Use a third-party global DNS checker to ensure the CNAME records are resolving publicly.
Sign in to the Microsoft Defender portal, and navigate to Email & collaboration > Policies & rules > Threat policies > Email authentication settings > DKIM.
Select your domain from the list and toggle the switch to enable DKIM signatures for messages sent from this domain.

Escalate to Microsoft Support for a Service-Side Fix
If DNS verification passes but the error persists in both the portal and PowerShell, the issue requires backend intervention from Microsoft.
Discover a Seamless, Free Alternative to Microsoft Office
While resolving complex backend administrative tasks in Microsoft 365, you can maintain seamless daily productivity. WPS Office offers a free, lightweight, and highly compatible alternative for all your document processing needs without the steep learning curve or administrative overhead.
- 1. Download the Installer: Visit the official WPS Office website and click on the 'Free Download' button.
- 2. Install WPS Office: Run the downloaded installation file and follow the on-screen instructions to complete the setup.
- 3. Start Creating: Launch WPS Office and instantly start creating or editing your documents, spreadsheets, and presentations.

Frequently Asked Questions
Why does Microsoft 365 DKIM setup show 'Error in retrieving encrypted key'?
This error typically occurs when the required DNS CNAME records haven't fully propagated, or there is a backend synchronization issue on Microsoft's servers preventing the generation of the DKIM keys.
How long does DKIM DNS propagation take for Microsoft 365?
DNS propagation for DKIM CNAME records usually takes between a few minutes to 48 hours, depending on your domain registrar and TTL (Time to Live) configuration.
Can I use PowerShell to bypass the Defender portal DKIM error?
You can attempt to create the DKIM keys using the Exchange Online PowerShell cmdlet New-DkimSigningConfig. However, if it is a backend service issue, PowerShell will often return the exact same encrypted-key error.
Does the DKIM encrypted key error affect the default onmicrosoft.com domain?
Yes, although Microsoft typically creates a default DKIM signing configuration for the initial onmicrosoft.com domain, backend provisioning glitches can occasionally cause the encrypted key error for the default domain as well.




