Google Workspace SPF, DKIM & DMARC setup: the exact clicks
Google Workspace sends your mail, but it does not authenticate it by default. SPF and DMARC live in your DNS and DKIM starts in the Admin console — here are the exact clicks and copy-paste records to get all three right.
What are the three things you need to set up?
Email authentication has three parts, and they belong in two different places:
- SPF — a TXT record at your domain root, added in your DNS host (your registrar, not Google). It lists Google's servers as authorized senders.
- DKIM — a key generated in the Google Admin console, then published as a TXT record at google._domainkey in your DNS. Google then signs every outgoing email with your domain.
- DMARC — a TXT record at _dmarc, added in your DNS. It tells receivers what to do when SPF and DKIM fail.
Do them in this order — SPF, then DKIM, then DMARC — and start DMARC in monitor mode. You'll need a super admin account for the Admin console steps.
Step 1: Add the SPF record in your DNS
Log in to your domain host (Spaceship, GoDaddy, Cloudflare, or wherever your name servers point) and find the DNS records page. Add this TXT record at the root of your domain (often labelled @):
v=spf1 include:_spf.google.com ~allTwo things to get right here. First, a domain can have only one SPF record — if you already have one from another sender (for example include:mailgun.org), merge the includes into a single record instead of adding a second. Second, ~all (softfail) is Google's default and the safe choice to start; -all (hard fail) is stricter but can bounce mail from senders you forgot. See the SPF guide for how the syntax works.
Step 2: Generate your DKIM key in the Admin console
Sign in to admin.google.com with a super admin account, then follow these clicks exactly:
- Go to Apps → Google Workspace → Gmail.
- Click Authenticate email.
- Select your domain from the dropdown.
- Click Generate new record.
- Set the DKIM key bit length to 2048-bit (recommended) and leave the selector prefix as google unless you have a reason to change it.
- Click Generate. Google shows you the DNS host name (google._domainkey) and the TXT record value — a long string containing your public key. Copy both; keep this tab open.
Step 3: Publish the DKIM record in DNS, then click "Start authentication"
Back in your DNS host, add a TXT record with host google._domainkey and paste in the full key value Google generated. Paste the entire value — some DNS panels truncate long strings, and a cut-off key will not verify.
Then return to the Admin console (Gmail → Authenticate email) and click Start authentication for your domain. Google checks DNS for the key; propagation can take up to 48 hours, and if Google can't see the record yet, just wait and click again later. Once it succeeds, the status changes to "Authenticating email" and your outbound mail gets signed.
Step 4: Add a DMARC record — start at p=none
Add one more TXT record in your DNS, this time at host _dmarc:
v=DMARC1; p=none; rua=mailto:dmarc@yourdomain.com;Replace dmarc@yourdomain.com with an inbox you control. Starting at p=none puts DMARC in monitor mode: receivers check your mail and send you aggregate reports, but take no action on failures. That's deliberate — you watch the reports for a week or two, confirm every legitimate sender passes, and only then move to p=quarantine and eventually p=reject. The DMARC rollout guide covers that path in detail.
How do I verify everything is working?
Send a test email from your Workspace account to another inbox (a personal Gmail is fine), open the message, and view the original headers — look for spf=pass, dkim=pass, and dmarc=pass in the authentication results. For a readable breakdown, paste those headers into the free email header analyzer, and run the SPF and DMARC audit tools on your domain to review the records you published.
What are the most common mistakes?
- Clicking "Start authentication" before DNS propagates. Google can't see the key yet. Wait, then click again — nothing breaks in the meantime.
- Publishing two SPF records. Multiple records invalidate SPF entirely; merge everything into one.
- Truncating the DKIM key when pasting. It's long — copy the whole value and confirm it saved in full.
- Starting DMARC at p=reject on day one. One forgotten sending service and its mail starts bouncing. Monitor first.
- Using -all while other tools also send. If a CRM or outreach tool sends as your domain, it must be in your SPF record or it will fail.
Want authentication done for you, correctly the first time?
I set up SPF, DKIM and DMARC for Google Workspace and cold email sending tools — DNS records, key generation, verification, and monitoring.
WhatsApp Saqib See packages