DKIM Key Rotation now results in invalid DKIM signature

%3CLINGO-SUB%20id%3D%22lingo-sub-1383188%22%20slang%3D%22en-US%22%3EDKIM%20Key%20Rotation%20now%20results%20in%20invalid%20DKIM%20signature%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1383188%22%20slang%3D%22en-US%22%3E%3CP%3EHi%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIn%20office%20365%20exchange%20admin%20center%2C%20DKIM%2C%20I%20clicked%20to%20Rotate%20the%20DKIM%20keys.%3C%2FP%3E%3CP%3EThe%20status%20for%20my%20domain%20now%20says%20%22Rotating%20keys%20for%20this%20domain%20and%20signing%20DKIM%20signatures.%22%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20was%20in%20the%20belief%20that%20Microsoft%20designed%20this%20process%20to%20be%20non-intrusive%2C%20by%20having%20two%20selectors.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EHowever%2C%20for%20me%20it%20doesn't%20work%20non-intrusive%20at%20all.%20Since%20I%20requested%20dkim%20key%20rotation%20all%20our%20outgoing%20emails%20result%20in%20an%20error%20at%20receiving%20domains%2C%20saying%20the%20DKIM%20signature%20of%20the%20email%20is%20invalid.%20I've%20checked%20the%20headers%2C%20and%20indeed%20our%20outgoing%20emails%20now%20refer%20to%20selector2%20instead%20of%20selector1.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E1)%20how%20long%20does%20it%20take%20before%20the%20status%20changes%20from%20%22rotating%20keys%22%20back%20to%20%22Signing%20DKIM%20signatures%20for%20this%20domain.%22%3F%20It's%20been%20like%20this%20already%20for%20a%20few%20hours.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E2)%20how%20is%20it%20possible%20that%20rotating%20keys%20all%20of%20a%20sudden%20invalidates%20the%20signature%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E3)%20how%20can%20I%20rotate%20back%20to%20selector1%20as%20apparently%20this%20was%20a%20working%20situation%20versus%20selector2%20resulting%20in%20invalid%20signatures%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThank%20you%2C%3C%2FP%3E%3CP%3EPatrick%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-1383188%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EAdmin%20App%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EExchange%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EOffice%20365%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1384185%22%20slang%3D%22en-US%22%3ERe%3A%20DKIM%20Key%20Rotation%20now%20results%20in%20invalid%20DKIM%20signature%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1384185%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F664854%22%20target%3D%22_blank%22%3E%40patrickcoom%3C%2FA%3E%26nbsp%3BHello%20Patrick%2C%20I'm%20on%20the%20run%20so%20just%20gonna%20attach%20this%20link%20in%20case%20you%20haven't%20seen%20it.%20It%20should%20at%20least%20shed%20some%20light%20on%20the%20process%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fsv-se%2Fmicrosoft-365%2Fsecurity%2Foffice-365-security%2Fuse-dkim-to-validate-outbound-email%3Fview%3Do365-worldwide%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fsv-se%2Fmicrosoft-365%2Fsecurity%2Foffice-365-security%2Fuse-dkim-to-validate-outbound-email%3Fview%3Do365-worldwide%3C%2FA%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20assume%20your%20not%20using%20any%20custom%20domains.%26nbsp%3B%3CSPAN%3ETypically%20Microsoft%20automatically%20rotates%20your%20DKIM%20keys.%20Did%20you%20upgrade%20to%202048%3F%26nbsp%3B%3C%2FSPAN%3E%3CSPAN%3EBy%20the%20way%2C%20it's%20very%20common%20with%20DNS%20misconfiguration.%3C%2FSPAN%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1388546%22%20slang%3D%22en-US%22%3ERe%3A%20DKIM%20Key%20Rotation%20now%20results%20in%20invalid%20DKIM%20signature%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1388546%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F664854%22%20target%3D%22_blank%22%3E%40patrickcoom%3C%2FA%3E%26nbsp%3BDid%20this%20get%20sorted%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EHave%20a%20look%20at%20this%20conversation%2C%20scroll%20down%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fexchange%2Fdkim-selector1-record-missing-at-365%2Fm-p%2F1388497%23M5038%22%20target%3D%22_blank%22%3Ehttps%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fexchange%2Fdkim-selector1-record-missing-at-365%2Fm-p%2F1388497%23M5038%3C%2FA%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E
Highlighted
Occasional Contributor

Hi,

 

In office 365 exchange admin center, DKIM, I clicked to Rotate the DKIM keys.

The status for my domain now says "Rotating keys for this domain and signing DKIM signatures."

 

I was in the belief that Microsoft designed this process to be non-intrusive, by having two selectors.

 

However, for me it doesn't work non-intrusive at all. Since I requested dkim key rotation all our outgoing emails result in an error at receiving domains, saying the DKIM signature of the email is invalid. I've checked the headers, and indeed our outgoing emails now refer to selector2 instead of selector1.

 

1) how long does it take before the status changes from "rotating keys" back to "Signing DKIM signatures for this domain."? It's been like this already for a few hours.

 

2) how is it possible that rotating keys all of a sudden invalidates the signature?

 

3) how can I rotate back to selector1 as apparently this was a working situation versus selector2 resulting in invalid signatures?

 

Thank you,

Patrick

 

2 Replies
Highlighted

@patrickcoom Hello Patrick, I'm on the run so just gonna attach this link in case you haven't seen it. It should at least shed some light on the process https://docs.microsoft.com/sv-se/microsoft-365/security/office-365-security/use-dkim-to-validate-out...

 

I assume your not using any custom domains. Typically Microsoft automatically rotates your DKIM keys. Did you upgrade to 2048? By the way, it's very common with DNS misconfiguration.

Highlighted