How to Fix SPF and DKIM After Moving a Domain from GoDaddy to Microsoft 365
Question details
The user needs to resolve email authentication (SPF and DKIM) failures that occur after migrating a domain from GoDaddy to Microsoft 365.

- Product
- Microsoft 365
- Device & OS
- not provided
- Scenario
- Migrating a domain from a GoDaddy federated tenant to a standard Microsoft 365 tenant, resulting in persistent authentication errors.
- Observed behavior
- Emails fail SPF and DKIM checks, and the Microsoft 365 Defender portal continues to display old GoDaddy tenant references (like NETORGFT) when attempting to configure new DKIM keys.
Ensure you have administrator access to both your DNS hosting provider and the Microsoft 365 Defender portal. Do not generate new DKIM keys until you verify that GoDaddy has fully released your tenant connection.
Disconnect GoDaddy Tenant and Update DNS Records
This solution resolves the federation conflict and establishes proper email authentication for your standard Microsoft 365 tenant.
GoDaddy creates a federated tenant for domains managed through their Microsoft 365 offering. When migrating to a standard Microsoft 365 tenant, this connection must be completely broken before new DKIM keys can be properly generated and applied.
Contact GoDaddy support or use PowerShell to ensure the federated tenant connection is completely removed and defederated from your domain.
Log into your domain's DNS provider. Create or update your TXT record for SPF to exactly 'v=spf1 include:spf.protection.outlook.com -all' to authorize Microsoft 365 sending services.
Navigate to the Microsoft 365 Defender portal. Go to Email & Collaboration > Policies & Rules > Threat policies > Email authentication settings > DKIM, and select your domain to create new keys.
Copy the new DKIM CNAME records provided in the Microsoft 365 Defender portal and publish them in your domain's DNS settings.
Allow up to 48 hours for the DNS changes to propagate globally, and monitor your DMARC reports to ensure emails are passing SPF and DKIM checks.
Stay Productive with WPS Office During Domain Migrations
While resolving complex Microsoft 365 and GoDaddy DNS issues, ensure your daily workflow remains uninterrupted. WPS Office offers a free, lightweight, and fully compatible suite for your business documents without the hassle of tenant migrations.

Frequently Asked Questions
Why does my Microsoft 365 portal still show NETORGFT for my domain?
GoDaddy automatically assigns a NETORGFT routing domain for federated tenants. If this still shows up after your migration, the federation connection hasn't been completely severed on the backend, or the system requires more time to sync.
How long does it take for new SPF and DKIM records to take effect?
DNS propagation typically takes anywhere from a few hours up to 48 hours. During this transition period, some emails might continue to fail authentication checks.
What should my SPF record look like for Microsoft 365?
A standard Microsoft 365 SPF record is a TXT record containing the value 'v=spf1 include:spf.protection.outlook.com -all'. Ensure you do not have multiple SPF records for a single domain, as this will cause authentication failures.
What if Microsoft 365 refuses to generate new DKIM keys?
If the Microsoft 365 Defender portal is stuck trying to generate keys for the old GoDaddy domain reference, you will need to open a support ticket with Microsoft 365 to have them manually clear the old DKIM configuration on their backend servers.




