Site AI Auditod Internet Solutions

Google Workspace SPF, DKIM and DMARC Setup, Step by Step

14 sierpnia 2026Czas czytania: 8 minDostarczalność e-maili
Google Workspace SPF, DKIM and DMARC Setup, Step by Step

Short answer: For Google Workspace, publish one SPF record that contains include:_spf.google.com, generate a 2048-bit DKIM key in the Admin console (Apps, Google Workspace, Gmail, Authenticate email), publish it as a TXT record at google._domainkey and press “Start authentication”, then add a DMARC record at _dmarc starting with p=none and a report address. Confirm with “Show original” in Gmail that SPF, DKIM and DMARC all show PASS.

Why a Workspace domain still needs manual setup

Activating Gmail for your domain only requires MX records and domain verification. Mail flows immediately, so many businesses stop there. But without SPF, custom DKIM and DMARC, messages from your Workspace mailboxes are less trusted by other providers, and nothing stops criminals from sending mail that looks like it comes from your domain.

Until you set up your own DKIM key, Google signs your outgoing mail with a default key for a Google-owned domain. That signature passes DKIM, but it does not align with your From address, so DMARC relies entirely on SPF. When mail is forwarded, SPF breaks and DMARC fails. A custom DKIM key for your own domain fixes that and is the single most important step after activation.

The setup takes perhaps half an hour of work, spread over a day because of DNS propagation. You need access to two places: the Google Admin console with super administrator rights, and the DNS panel of your domain, which may be at your registrar, your hosting company or a DNS service.

Step 1: check the MX records

Before authentication, make sure incoming mail is routed to Google. Current Google documentation for new setups lists a single MX record: smtp.google.com with priority 1. Older setups use five records (ASPMX.L.GOOGLE.COM and its alternates), and Google continues to support them. Either set is fine; a mix with another provider’s records is not.

Look them up with dig MX yourdomain.com +short. If you see leftovers from a previous host, remove them, otherwise part of your incoming mail may go to a server nobody reads.

Step 2: publish the SPF record

If Workspace is the only service that sends mail for your domain, the SPF record is simply:

v=spf1 include:_spf.google.com ~all

Publish it as a TXT record at the root of the domain (@). If other services also send mail with your domain in the envelope sender, add their includes to the same record, for example:

v=spf1 include:_spf.google.com include:servers.example-newsletter.com ~all

Points to watch:

Step 3: generate and publish the DKIM key

  1. In the Admin console, go to Apps > Google Workspace > Gmail > Authenticate email.
  2. Select your domain. If you have several domains, each needs its own key.
  3. Click Generate new record. Choose a key length of 2048 bits unless your DNS host cannot store long TXT records, in which case 1024 still works. Keep the default prefix selector google unless you already use that name.
  4. Copy the host name (google._domainkey) and the TXT value, which begins with v=DKIM1; k=rsa; p=.
  5. In your DNS panel, create a TXT record with that host name and value. Enter only google._domainkey if the panel adds your domain automatically.
  6. Wait until the record is visible. Check with dig TXT google._domainkey.yourdomain.com +short.
  7. Return to the Admin console and click Start authentication. The status should change to “Authenticating email with DKIM”.

The last step is the one most often forgotten. The key can sit in DNS for years while Google continues to sign with its default domain, because nobody pressed the button. If you see a message that the record cannot be found, wait longer for DNS; Google says it can take up to 48 hours, although it is usually much faster.

Step 4: add the DMARC record

Create a TXT record at the host _dmarc with a starting policy:

v=DMARC1; p=none; rua=mailto:[email protected]

Create the dmarc@ mailbox or a group first, or use a report-processing service’s address. With p=none nothing changes for delivery, but daily reports start arriving from Gmail, Yahoo, Microsoft and others. Use them to find any other service that sends with your domain and still needs authentication, then move to p=quarantine and eventually p=reject.

A tip for Workspace admins: a Google Group used as the DMARC report address can collect reports for several people without using a paid licence. Configure it to accept mail from external senders, or reports will be rejected.

Step 5: verify in Gmail

  1. From a Workspace mailbox, send a message to an external address, ideally a personal Gmail account and an Outlook.com account.
  2. In Gmail, open the message, click the three-dot menu and choose Show original.
  3. The summary at the top shows SPF, DKIM and DMARC. All three should read PASS, and DKIM should mention your domain, not a Google-owned one.
  4. In the raw headers, Authentication-Results should show dkim=pass [email protected], spf=pass and dmarc=pass.

Repeat the test for every other system that sends as your domain: website forms, the shop, the CRM, the newsletter tool. Those are separate from Workspace and need their own DKIM configuration.

Website and device mail through Workspace

Many small businesses want their website contact form, online shop or office scanner to send mail through Google so that it inherits the same authentication. There are two common ways to do it:

Either option is better than letting the web server send mail directly. Direct mail from a web host is not covered by Google’s SPF include and carries no DKIM signature for your domain, so it fails DMARC as soon as you enforce a policy. Keep an eye on Workspace’s sending limits for high-volume forms or shops; bulk notifications are better handled by a dedicated transactional mail service with its own DKIM key for your domain.

Common Workspace mistakes

MistakeWhat you seeFix
DKIM key published but authentication not startedDKIM passes for a Google domain, DMARC depends on SPFPress “Start authentication” in the Admin console
Two SPF records after adding a newsletter toolspf=permerrorMerge both into one record
Domain appended twice to the DKIM hostAdmin console cannot find the recordEnter only google._domainkey in the host field
Key truncated by the DNS paneldkim=fail or permerrorRe-enter the full value; split into quoted strings if needed, or use 1024 bits
Secondary domains forgottenMail from alias domains fails DMARCGenerate a DKIM key and publish SPF and DMARC for each domain
Old MX records from previous hostSome incoming mail missingKeep only Google’s MX records

Beyond the basics

Once the three records are in place and your DMARC reports look clean, a few further steps are worth considering:

Site AI Audit checks the published SPF (including its lookup limit), DKIM, DMARC and MX records for a domain from the outside, and explains every finding in plain words next to the website’s SEO, speed and SSL results. It is a quick way to confirm that the Workspace setup is really visible to the world, and paid plans keep checking so a record deleted during later DNS work is noticed. You can check your domain for free.

Related reading

The bottom line

Google Workspace needs three authentication records beyond MX: SPF with Google’s include, a custom DKIM key that is actually switched on, and a DMARC record with reports. Publish them, verify with “Show original”, and then use DMARC reports to bring every other sending service into line before you enforce the policy.

FAQ

What is the SPF record for Google Workspace?

The basic record is v=spf1 include:_spf.google.com ~all. If other services send mail for your domain, add their includes to the same record rather than creating a second one.

Where do I find the DKIM key in Google Workspace?

In the Admin console under Apps, Google Workspace, Gmail, Authenticate email. Select the domain, generate a new record, publish it in DNS and then click Start authentication.

Why does Gmail show DKIM pass with a different domain?

Because custom DKIM is not active yet, so Google signs with its default domain. Generate your own key, publish it and start authentication to sign with your domain.

Should I use a 2048-bit or 1024-bit DKIM key in Workspace?

Use 2048 bits if your DNS host supports long TXT records. If the host truncates the key, 1024 bits still works, but consider moving DNS to a provider that handles long records.

Does Google Workspace create a DMARC record automatically?

No. You must publish the DMARC TXT record at _dmarc yourself in your DNS panel. Start with p=none and a report address, then tighten the policy.

Do I need separate records for alias domains?

Yes. Each domain that appears in From addresses needs its own SPF record, its own DKIM key generated in the Admin console and its own DMARC record.

#DKIM#DMARC#Email Authentication#Google Workspace#SPF
Sprawdź swoją stronę — za darmo.Co poprawić na Twojej stronie — i od czego zacząć.
Zacznij za darmo
Internet Solutions

Więcej od naszego zespołu

Stworzone przez Internet Solutions. Wypróbuj nasze pozostałe produkty — każdy oszczędza czas na swój sposób.

internet-solutions.net ↗
Site AI Audit
Przegląd prywatności

Ta strona używa plików cookie, abyśmy mogli zapewnić Ci jak najlepsze wrażenia. Informacje z plików cookie są przechowywane w Twojej przeglądarce i pełnią funkcje takie jak rozpoznawanie Cię po powrocie na stronę oraz pomagają naszemu zespołowi zrozumieć, które sekcje strony są dla Ciebie najciekawsze i najbardziej przydatne.