logo
search
Security Policy Errors

How to Fix Microsoft 365 DKIM Error Retrieving Encrypted Key

Ayan MasoodAyan Masood Sep 30, 2026 868 views

Question details

The user is encountering an 'Error in retrieving encrypted key' message when attempting to configure DKIM for a Microsoft 365 domain.

How to Fix Microsoft 365 DKIM Error Retrieving Encrypted Key
Product
Microsoft 365
Device & OS
not provided
Scenario
Setting up DKIM signatures for custom domains or the default onmicrosoft.com domain using the Microsoft Defender portal.
Observed behavior
The DKIM setup fails with an encrypted key retrieval error, even after successful domain verification and valid DNS checks.
Before you start

Ensure you have global administrator or Exchange administrator privileges in Microsoft 365, and verify that your domain's DNS CNAME records have had at least 24 to 48 hours to fully propagate.

Solution 1Recommended

Verify DNS CNAME Records and Re-enable DKIM

Confirm that the correct DKIM CNAME records are published and fully propagated before attempting to enable DKIM in the Defender portal.

Microsoft 365 relies on correctly propagated CNAME records to generate and retrieve DKIM keys. If your domain's DNS is not fully propagated across global servers, the Microsoft Defender portal may return encrypted-key errors during the activation process.

1
Check DNS Provider

Log in to your DNS hosting provider's control panel and verify that the two DKIM CNAME records provided by Microsoft are properly published for your custom domain.

2
Wait for Propagation

Allow up to 48 hours for full DNS propagation. Use a third-party global DNS checker to ensure the CNAME records are resolving publicly.

3
Navigate to Defender Portal

Sign in to the Microsoft Defender portal, and navigate to Email & collaboration > Policies & rules > Threat policies > Email authentication settings > DKIM.

4
Enable DKIM Signatures

Select your domain from the list and toggle the switch to enable DKIM signatures for messages sent from this domain.

Verify DNS CNAME Records and Re-enable DKIM
Default Domains: For the default onmicrosoft.com domain, Microsoft automatically handles the DNS records. If you experience this error on the default domain, proceed to escalate to Microsoft Support.
Free Microsoft Office alternative

Discover a Seamless, Free Alternative to Microsoft Office

While resolving complex backend administrative tasks in Microsoft 365, you can maintain seamless daily productivity. WPS Office offers a free, lightweight, and highly compatible alternative for all your document processing needs without the steep learning curve or administrative overhead.

  1. 1. Download the Installer: Visit the official WPS Office website and click on the 'Free Download' button.
  2. 2. Install WPS Office: Run the downloaded installation file and follow the on-screen instructions to complete the setup.
  3. 3. Start Creating: Launch WPS Office and instantly start creating or editing your documents, spreadsheets, and presentations.
Fully compatible with Microsoft Word, Excel, and PowerPoint formats (.docx, .xlsx, .pptx).Lightweight architecture that runs smoothly on almost any device without complex IT configuration.Familiar and intuitive user interface that requires zero learning curve for a seamless migration.Built-in PDF editing, merging, and conversion tools for comprehensive document management.
microsoft office alternative - wps office

Frequently Asked Questions

Why does Microsoft 365 DKIM setup show 'Error in retrieving encrypted key'?

This error typically occurs when the required DNS CNAME records haven't fully propagated, or there is a backend synchronization issue on Microsoft's servers preventing the generation of the DKIM keys.

How long does DKIM DNS propagation take for Microsoft 365?

DNS propagation for DKIM CNAME records usually takes between a few minutes to 48 hours, depending on your domain registrar and TTL (Time to Live) configuration.

Can I use PowerShell to bypass the Defender portal DKIM error?

You can attempt to create the DKIM keys using the Exchange Online PowerShell cmdlet New-DkimSigningConfig. However, if it is a backend service issue, PowerShell will often return the exact same encrypted-key error.

Does the DKIM encrypted key error affect the default onmicrosoft.com domain?

Yes, although Microsoft typically creates a default DKIM signing configuration for the initial onmicrosoft.com domain, backend provisioning glitches can occasionally cause the encrypted key error for the default domain as well.