Google Workspace SPF, DKIM and DMARC: the three records to add
The SPF, DKIM and DMARC records a Google Workspace domain publishes, where each value comes from in the Admin console, and how to check them.
On this page
A Google Workspace domain authenticates its mail with three DNS TXT records: an SPF record on the domain itself, which Google (opens in a new tab) gives as v=spf1 include:_spf.google.com ~all when Workspace is your only sender; a DKIM record whose name and key you generate for your domain in the Admin console (opens in a new tab) before turning signing on; and a DMARC record at _dmarc, which Google (opens in a new tab) recommends starting at a policy of none. Publish them at your domain's DNS host, then check what the domain publishes.
The three records at a glance
- SPF: host
@, valuev=spf1 include:_spf.google.com ~all, from Google's SPF set-up guide (opens in a new tab) for Workspace as the only sender. - DKIM: host
google._domainkeywith the default selector, and as value the key the Admin console generates for your domain, starting with something likev=DKIM1(Google (opens in a new tab)). It is unique to your domain. - DMARC: host
_dmarc, with a starting value such asv=DMARC1; p=none; rua=mailto:[email protected], from Google's DMARC set-up guide (opens in a new tab) and DemiSignal's DMARC record generator.
All three are TXT records. Replace [email protected] with a reporting address you actually read.
Check your domain now
See the SPF, DKIM and DMARC records your domain publishes and what to fix first. Free, no account needed.
SPF
Sender Policy Framework (SPF) (opens in a new tab) lets a domain publish, in the Domain Name System (DNS) (opens in a new tab), which hosts may use its name, and receivers test the sending server against that list.
If you use only Google Workspace to send email, Google's SPF set-up guide (opens in a new tab) gives this record:
v=spf1 include:_spf.google.com ~all
Add it as a TXT record at your domain host. If the record is for the domain itself rather than a subdomain, enter @ as the host. Some domain hosts require the record string in quotes, so check your host's help documentation. Each domain must have its own SPF record, and if you use subdomains, each needs its own SPF record as well. It can take up to 48 hours for SPF authentication to start working.
Google recommends ending the record with ~all. In the SPF standard, the ~ qualifier gives servers the record doesn't list a softfail (RFC 7208 section 4.6.2 (opens in a new tab)): receivers should not reject a message based on a softfail alone, but may subject it to closer scrutiny than normal (section 8.5 (opens in a new tab)).
Checked against live DNS, _spf.google.com publishes Google's sending ranges directly as ip4 and ip6 terms, ending in ~all. DemiSignal's SPF record generator has a Google Workspace option that adds include:_spf.google.com for you.
DKIM
DomainKeys Identified Mail (DKIM) (opens in a new tab) lets a domain claim some responsibility for a message, validated through a cryptographic signature and a public key the receiver retrieves from the signer's domain. Google's DKIM set-up guide (opens in a new tab) has Workspace admins generate the key pair in the Admin console and add the public key to their domain; receiving servers use it to read the signature on mail from that domain.
Before you start:
- If your domain provider is Squarespace, the DKIM key is created and added to your DNS records automatically.
- You might not need to set up DKIM if your domain already has it set up by default, or if you bought the domain from a Google partner when you signed up for Google Workspace.
- If you use outbound gateways, check that their settings don't interfere with DKIM.
1. Generate the key
You need to be signed in as a super administrator. After you turn on Gmail for your organization, you must wait 24–72 hours before you can get your DKIM key.
- In the Google Admin console, go to Menu, Apps, Google Workspace, Gmail.
- Click Authenticate email, and select your domain in the Selected domain menu.
- Click Generate New Record. Choose a 2048-bit key if your domain provider supports it, otherwise 1024.
- Keep the default prefix selector,
google, which Google recommends for Workspace. If your domain already uses a DKIM key with that prefix, enter a different one. - Copy the two values shown: the DNS Host name (the TXT record name) and the TXT record value (the DKIM key).
Don't click Start authentication yet.
2. Publish the key
At your domain host, add a TXT record with that host name, for example google._domainkey, and the key as its value; the value starts with something like v=DKIM1. Google issues a unique DKIM key for each domain, so use the one your Admin console generated, never a value copied from another domain. After adding the key, it can take up to 48 hours for DKIM authentication to start working.
3. Turn on signing and verify
Back in Authenticate email, select the domain and click Start authentication. When DKIM is working, the status changes to "Authenticating email with DKIM".
To verify, send a message to someone who uses Gmail or Google Workspace; a test message to yourself doesn't show it. In Gmail, open the message, click More next to Reply, then Show original, and look for Authentication-Results, where DKIM should show something like DKIM=pass. If that message's header has no DKIM line, the message wasn't signed with DKIM. Google's advice is to verify you completed every step, then work through its Troubleshoot DKIM issues guide.
DMARC
DMARC (opens in a new tab) (Domain-based Message Authentication, Reporting, and Conformance) lets a domain owner publish a DNS TXT record describing its authentication policies and request specific handling for mail that fails validation; a DMARC pass requires an SPF or DKIM pass for a domain aligned with the From domain, which the standard calls the Author Domain (RFC 9989 section 1 (opens in a new tab)).
Google's DMARC set-up guide (opens in a new tab) sets the order: turn on SPF and/or DKIM first, and allow 48 hours before setting up DMARC. Then add a TXT record at _dmarc.example.com, with your domain in place of example.com. Some domain hosts add the domain name automatically, so check the saved name afterwards.
When you start using DMARC, Google recommends a policy of none. This is the starting record DemiSignal's DMARC record generator writes, with monitoring first:
v=DMARC1; p=none; rua=mailto:[email protected]
For the rua report address, Google advises against your own email address and suggests a dedicated mailbox, a group, or a third-party service that specializes in DMARC reports. If the address is on another domain, that domain must publish a TXT record authorizing the reports, or receivers don't send them; reporting services set this up for you.
The No DMARC record found guide covers a record that doesn't show up, and DMARC policy not enabled covers moving from p=none to quarantine or reject.
Other services that send as your domain
Keep one SPF record and add each sender to it with the include: tag (Google's SPF set-up guide (opens in a new tab)). Google's own example for Workspace and Zendesk:
v=spf1 include:_spf.google.com include:mail.zendesk.com ~all
DKIM works per sender. For mail sent from Google Workspace, the key to verify is the one you added to your domain; for mail sent by a third-party service, follow that service's documentation for its DKIM key (Google Workspace (opens in a new tab)).
Gmail's sender requirements
If you send email to personal Gmail accounts, Google requires email authentication: all senders must set up SPF or DKIM, and bulk senders, those sending more than 5,000 messages a day, must set up SPF, DKIM and DMARC (Google (opens in a new tab)).
Need hands-on help?
DemiEmail (opens in a new tab) is the hands-on side: DemiSignal provides ongoing email authentication monitoring, and DemiEmail handles scoped technical work. It configures or troubleshoots SPF, DKIM and DMARC across the services sending email for a business, from a sending-service and DNS review to verification and a documented handover. The work, required access, deliverables and price are agreed as the scope, so you know what it costs before the work begins.
Check your domain
DemiSignal's check reads the public DNS records of the domain you enter and shows your SPF, DKIM and DMARC records, with no account needed. DKIM keys sit under selector names your email provider chooses, and the check tries commonly used selectors, so a key published under a selector it doesn't try won't show up there. A missing DKIM result is not proof that your domain has no key; your provider's admin console shows the selector it uses.
Sources
- Google Workspace: Set up SPF (opens in a new tab)
- Google Workspace: Set up DKIM (opens in a new tab)
- Google Workspace: Set up DMARC (opens in a new tab)
- Google Workspace: Troubleshoot DMARC issues (opens in a new tab)
- Google Workspace: About TXT records (opens in a new tab)
- RFC 7208: Sender Policy Framework (SPF), section 1 (opens in a new tab)
- RFC 7208 section 4.6.2: Mechanisms (opens in a new tab)
- RFC 7208 section 8.5: Softfail (opens in a new tab)
- RFC 6376: DomainKeys Identified Mail (DKIM) Signatures, section 1 (opens in a new tab)
- RFC 9989 (RFC Editor information page) (opens in a new tab)
- RFC 9989 section 1: Introduction (opens in a new tab)
- DemiEmail (opens in a new tab)
- DemiSignal: SPF, DKIM and DMARC check
- DemiSignal: SPF record generator
- DemiSignal: DMARC record generator
- DemiSignal: No DMARC record found
- DemiSignal: DMARC policy not enabled
Tools for this
-
SPF, DKIM and DMARC check
Check the email records a domain publishes today and see what to fix first.
-
SPF record generator
Build an SPF record for the services that send your email.
-
DMARC record generator
Build a DMARC record step by step, from monitoring to reject.
Frequently asked questions
What is the SPF record for Google Workspace?
If Google Workspace is the only service that sends email for your domain, Google gives v=spf1 include:_spf.google.com ~all, added as a TXT record with the host @. Other senders go into the same record with their own include.
Where do I find the Google Workspace DKIM record?
In the Google Admin console under Apps, Google Workspace, Gmail, Authenticate email: generate a new record, then copy the DNS host name and TXT record value it shows. Google issues a unique DKIM key for each domain.
Do I need DMARC for Google Workspace?
For email to personal Gmail accounts, Google requires SPF or DKIM from all senders, and SPF, DKIM and DMARC from bulk senders of more than 5,000 messages a day. When you start using DMARC, Google recommends a policy of none.
Check your domain now
See the SPF, DKIM and DMARC records your domain publishes and what to fix first. Free, no account needed.