How to Restore Default DKIM Settings for a Microsoft 365 Domain
Question details
A Microsoft 365 administrator needs to revert their domain's DKIM settings to Microsoft's default configuration and confirm if default DKIM functions properly alongside DMARC.

- Product
- Microsoft 365
- Device & OS
- not provided
- Scenario
- The user manually generated custom DKIM keys, added them to their DNS records, and enabled signing, but now wants to restore the original Microsoft 365 default DKIM setup and configure DMARC.
- Observed behavior
- Custom DKIM keys override the default Microsoft 365 DKIM signatures, raising questions about DMARC alignment and how to successfully roll back to the default state.
Before modifying your DKIM settings, ensure you have Global Administrator or Security Administrator permissions in Microsoft 365 and access to your domain's DNS hosting provider.
Revert to Microsoft 365 Default DKIM Settings
Use the Microsoft 365 Defender portal to disable custom DKIM signing and fall back to the default Microsoft signatures.
Microsoft 365 automatically sets up a default DKIM signature using the initial '.onmicrosoft.com' domain when you create your tenant. To restore this behavior, you must first disable custom DKIM signing for your primary domain and then remove the custom DNS records.
Sign in to the Microsoft 365 Defender portal. In the navigation pane, go to Email & Collaboration > Policies & Rules > Threat policies.
Under the Rules section, select DomainKeys Identified Mail (DKIM) to view the list of domains associated with your tenant.
Select your primary custom domain. In the flyout pane, toggle the switch for 'Sign messages for this domain with DKIM signatures' to Off. This action stops the use of your custom keys.
Log in to your DNS hosting provider's portal, locate the custom CNAME records you previously created for DKIM (usually starting with 'selector1' and 'selector2'), and delete them. Microsoft 365 will now default back to signing emails with its initial configuration.

Configure DMARC with Default DKIM
Set up a DMARC policy for your domain to protect against spoofing and phishing, working in conjunction with your active DKIM and SPF settings.
Looking for a Lightweight Office Suite Alternative?
While you manage your domain's email security and administrator settings, consider using WPS Office for your daily productivity tasks. It offers a lightweight, robust, and completely free alternative to heavy Office installations.
- 1. Download the Installer: Visit the official WPS Office website and click on the Free Download button.
- 2. Install WPS Office: Run the downloaded executable file and follow the quick installation prompts on your screen.
- 3. Open Your Files: Launch WPS Office and immediately start opening, editing, and saving your existing Microsoft Office documents without any compatibility issues.

Frequently Asked Questions
Does default Microsoft 365 DKIM work with DMARC?
Yes, default DKIM signs outgoing messages using the tenant's initial '.onmicrosoft.com' domain. DMARC evaluates both SPF and DKIM alignment. If your default DKIM signature does not perfectly match the custom domain in your 'From' address, DMARC can still pass if your SPF record is properly aligned. However, custom DKIM keys are strongly recommended for optimal DMARC compliance.
What is the difference between DKIM and DMARC?
DKIM (DomainKeys Identified Mail) adds a cryptographic digital signature to outgoing emails, allowing the receiving server to verify the sender's domain. DMARC (Domain-based Message Authentication, Reporting, and Conformance) is a policy layer that tells the receiving server what to do if an email fails SPF or DKIM checks, helping to prevent spoofing and phishing.
What happens if I delete my DKIM CNAME records without disabling it in Microsoft 365?
If you delete your custom CNAME records from your DNS provider but leave custom DKIM signing enabled in the Microsoft 365 Defender portal, your outgoing emails will continue to be signed with keys that receiving servers cannot verify. This will cause DKIM authentication failures and may result in your emails being marked as spam. Always disable signing in Microsoft 365 first.
Where can I view Microsoft's official DKIM and DMARC documentation?
You can find comprehensive configuration guides for DKIM and DMARC in the Microsoft Learn platform under the Microsoft 365 Security documentation section. Reviewing these guides is highly recommended before making broad changes to your domain's email authentication policies.




