Set up SPF, DKIM and DMARC for Google Workspace
The exact SPF, DKIM and DMARC records Google Workspace needs, where to add them and how to check they pass and align, so Google Workspace mail reaches the inbox.
Updated September 30, 2026
Google Workspace needs three records: include:_spf.google.com in your SPF record, a DKIM key you generate in the Admin console and publish as a TXT record at google._domainkey, and a DMARC record at _dmarc. Gmail already sends with your domain as the envelope sender, so SPF aligns out of the box. DKIM only aligns once you turn on your own key, because until then Google signs with a gappssmtp.com domain.
Records at a glance
| Host | Type | Value |
|---|---|---|
@ | TXT | v=spf1 include:_spf.google.com ~allOnly one SPF record per domain. If you already have one, add the include to it. |
google._domainkey | TXT | v=DKIM1; k=rsa; p=<key from the Admin console>Generated in Apps > Google Workspace > Gmail > Authenticate email. Copy it exactly. |
_dmarc | TXT | v=DMARC1; p=none; rua=mailto:<your report address>Start at p=none, then tighten once reports look clean. |
Set up SPF for Google Workspace
Google’s recommended record is v=spf1 include:_spf.google.com ~all. As of September 2026, _spf.google.com lists Google’s IP ranges directly, so the include costs one of your ten DNS lookups.
If other services also send as your domain, merge everything into one record. Two SPF records on the same name make SPF fail with a permanent error. For example, Google Workspace plus Mailgun and Microsoft 365:
v=spf1 include:_spf.google.com include:mailgun.org include:spf.protection.outlook.com ~allGoogle recommends ~all (soft fail). DMARC treats ~all and -all the same way: both count as an SPF failure, and the DMARC policy decides what happens. Keep an eye on the total lookup count as you add senders; SPF’s 10-lookup limit explains how to stay under it. If you use DMARC Dojo’s hosted SPF, you add senders in the dashboard instead of editing this record, and changes that would go over ten lookups are refused.
Set up DKIM in the Admin console
- Sign in to the Google Admin console as a super admin and go to Menu > Apps > Google Workspace > Gmail.
- Click Authenticate email and pick your domain from the Selected domain menu.
- Click Generate new record. Choose a 2048-bit key (use 1024 only if your DNS host can’t store a longer TXT value) and keep the default prefix selector,
google, unless another service already uses it. Click Generate. - Copy the DNS Host name (
google._domainkey) and the TXT record value and add them as a TXT record at your DNS host. - Back on the Authenticate email page, click Start authentication. The status changes to “Authenticating email with DKIM.”
Google says it can take up to 48 hours for DKIM to start working after you add the key. To confirm, send a message to a Gmail address, open it, choose Show original, and check that DKIM shows PASS with d= your own domain, not a gappssmtp.com domain.
Make it pass DMARC (alignment)
DMARC passes when SPF or DKIM passes and the domain it checked matches the domain in the From address. For mail sent from Gmail itself:
- SPF aligns by default. Gmail uses your address as the envelope sender (Return-Path), so a pass on
_spf.google.comcounts for your domain. - DKIM doesn’t align until you turn it on. Without your own key, Gmail signs with a default
d=*.gappssmtp.comsignature. It passes DKIM but doesn’t match your domain.
Relying on SPF alone is fragile: forwarding breaks SPF, while a DKIM signature survives most forwarding. So turn on DKIM before you move past p=none. Also check that routing rules, outbound gateways or signature tools that add footers don’t change messages after Google signs them. DMARC alignment covers the rules in more detail.
Add a DMARC record
Publish a TXT record at _dmarc with a monitoring policy and a report address:
v=DMARC1; p=none; rua=mailto:<your report address>Reports show every service sending as your domain. DMARC Dojo recognizes Google Workspace in those reports, so you can see at a glance whether Gmail traffic passes with alignment and spot other senders that still need setup. Once everything legitimate passes, move to quarantine and then reject, as described in moving from p=none to p=reject.
Check your Google DKIM key
Enter your domain to confirm the google._domainkey record is published, plus SPF and DMARC, with a score and the fixes to make.
Troubleshooting
- “Start authentication” fails or DKIM still shows the gappssmtp.com domain. The TXT record isn’t visible yet or doesn’t match. Compare the published value with the one in the Admin console, and allow up to 48 hours.
- The record lands at the wrong name. Many DNS hosts add your domain automatically, so entering
google._domainkey.example.comcreatesgoogle._domainkey.example.com.example.com. Enter justgoogle._domainkey. - The key was truncated. A DNS host that cuts TXT values at 255 characters breaks a 2048-bit key. Split it into quoted strings or generate a 1024-bit key.
- DKIM fails only for some messages. An outbound gateway, disclaimer tool or mailing list is changing the message after Google signs it.
- SPF fails with “permerror”. You have two SPF records, or your combined record needs more than ten lookups. Merge them and check the count with the SPF checker.
Frequently asked questions
Does Google Workspace sign my mail with DKIM automatically?
Yes, but with a default key for a gappssmtp.com domain, not your domain. That signature passes DKIM but doesn’t align for DMARC, so you still need to generate your own key and click Start authentication.
Should I choose a 2048-bit or 1024-bit DKIM key?
Choose 2048-bit. Use 1024-bit only if your DNS host can’t store the longer value, even as split strings. You can generate a new 2048-bit key later and switch to it.
Can I change the google selector?
Yes. The prefix selector is set when you generate the key. Change it only if another service already publishes a key at google._domainkey, or when you rotate to a new key and want both to coexist.
Do I need a separate DKIM key for each domain in Google Workspace?
Yes. Each domain and each secondary domain that sends mail needs its own key, generated by picking that domain in the Selected domain menu.
Is include:_spf.google.com enough if I also use a newsletter tool?
No. It covers only mail sent through Google’s servers. Every other service that sends as your domain needs its own SPF include or, better, its own aligned DKIM signature.