Google Workspace SPF, DKIM and DMARC: the three DNS records step by step
Published 7 October 20268 min readBy the SmoothSeen editorial team
To authenticate Google Workspace email, publish three TXT records in your domain's DNS: SPF at the root with v=spf1 include:_spf.google.com ~all, the DKIM key the Admin console generates at google._domainkey, and DMARC at _dmarc, starting with p=none. Turn DKIM on with "Start authentication" and leave 48 hours between steps.
Key points
- Google Workspace SPF is a single TXT record at the root of the domain containing include:_spf.google.com, and Google recommends ending it with ~all.
- The DKIM key is generated in the Admin console (Apps > Google Workspace > Gmail > Authenticate email), with 2048 bits and the google selector, and only starts signing once you click "Start authentication".
- DMARC goes on _dmarc, starts at p=none with rua reports, and Google asks you to wait 48 hours with SPF and DKIM working before publishing it.
- Since 1 February 2024 Gmail requires SPF or DKIM from every sender, and SPF, DKIM and DMARC from anyone sending more than 5,000 messages a day to personal Gmail accounts.
To check it on your own site: SEO audit
On this page
- What happens in Google Workspace and what happens in your DNS?
- Step 1: the SPF record
- Step 2: DKIM from the Admin console
- Step 3: DMARC, from p=none to p=reject
- The three example records for example.com
- What does Gmail require from senders?
- How to check it
- What SmoothSeen does with this
- What to do this week
- Frequently asked questions
Three definitions first. SPF is the list of servers allowed to send email for your domain. DKIM is a cryptographic signature your server adds to every message, which the recipient checks against a public key published in your DNS. DMARC tells the receiving server what to do with a message that passes neither SPF nor DKIM in alignment with the sender's domain, and where to send reports. This guide applies all three to Google Workspace, following Google's help pages as of 7 October 2026.
What happens in Google Workspace and what happens in your DNS?
- Record
- SPF
- Where it is generated
- You write it
- Where it is published
- Your domain's DNS, at the root
- Do you switch it on in the console?
- No: Google says there is nothing to do in the Admin console1
- Record
- DKIM
- Where it is generated
- Google Admin console
- Where it is published
- Your domain's DNS, at
google._domainkey - Do you switch it on in the console?
- Yes: "Start authentication"2
- Record
- DMARC
- Where it is generated
- You write it
- Where it is published
- Your domain's DNS, at
_dmarc - Do you switch it on in the console?
- No3
DNS is managed wherever you bought the domain or wherever its nameservers point (your registrar, Cloudflare, your hosting company). Google does not offer technical support for third-party domain providers2. If your company runs on Microsoft 365, the steps differ: see the guide to Microsoft 365 SPF, DKIM and DMARC.
Step 1: the SPF record
If Google Workspace is the only thing that sends your email, the record is1:
v=spf1 include:_spf.google.com ~allIt goes in as a TXT record at the root of the domain (@ in the host field). The rules worth sticking to:
- One SPF record per domain. Google puts it plainly: each domain can have one SPF record4. If you already have one, add Google's
include:to it rather than creating another. Microsoft explains what happens with two: SPF returns a permanent error (permerror)5. - Include everyone who sends on your behalf: the website (contact forms), the newsletter tool, the online shop, the help desk. Google publishes combined examples, such as
v=spf1 include:_spf.google.com include:servers.mcsv.net ~allfor Google Workspace plus Mailchimp1. - Stay within 10 DNS lookups. Every
include:counts, and so do nested ones. Google asks for no more than 10 references to other domains or servers4. - End with
~all. That is Google's recommendation: servers not on the list get flagged as suspicious1.
Every subdomain that sends email needs its own SPF record, and SPF can take up to 48 hours to start working1.
Step 2: DKIM from the Admin console
You need to be a super administrator. If you have only just turned on Gmail for your organisation, Google says to wait 24 to 72 hours before generating the key, or you may get an error2.
- In the Google Admin console, go to Menu > Apps > Google Workspace > Gmail.
- Click Authenticate email and pick the domain under Selected domain.
- Click Generate New Record.
- Choose the key length: 2048 if your DNS provider supports it (it is more secure); 1024 only if it does not.
- Leave the default prefix selector, google, unless your domain already has a DKIM key with that prefix.
- Click Generate and copy both values: the host name (
google._domainkey) and the TXT record value, which starts withv=DKIM1. - Do not click "Start authentication" yet.
Next, at your DNS provider, create a TXT record with that host and value. Some providers cap TXT record length, and a 2048-bit key is long; if yours truncates it, Google has a page on those limits2. DKIM can take up to 48 hours to work after you publish the key.
Once the key is published, go back to Authenticate email and click Start authentication. The status changes to "Authenticating email with DKIM"2. The console may keep warning you to update your DNS records for up to 48 hours; if the key is published correctly, Google says you can ignore it2.
Step 3: DMARC, from p=none to p=reject
Google asks you to have SPF and DKIM authenticating for at least 48 hours before publishing DMARC3. Beforehand, set up a group or a dedicated mailbox for reports: Google warns you may receive many every day and advises against using your own inbox3.
The record is a TXT on the host _dmarc (that is, _dmarc.example.com). The tags that matter:
- Tag
v- What it does
- Version, required and first
- Starting value
DMARC1
- Tag
p- What it does
- What to do with failures:
none,quarantineorreject - Starting value
none
- Tag
rua- What it does
- Address for aggregate reports
- Starting value
mailto:dmarc@example.com
- Tag
sp- What it does
- A different policy for subdomains
- Starting value
- Leave out: subdomains inherit the domain's policy
- Tag
adkim,aspf- What it does
- Strict (
s) or relaxed (r, the default) alignment - Starting value
- Leave out
Alignment is what makes DMARC stricter than SPF or DKIM on their own: the domain in the From: address the user sees must match the domain SPF validated or the domain DKIM signed with. A message passes DMARC if it passes at least one of the two with alignment3. Google warns that strict alignment can send legitimate mail from subdomains to spam or get it rejected; relaxed alignment is usually enough3.
Gmail does not send forensic reports, so the ruf tag does nothing there3. And a note on pct: Google's help still recommends it for gradual roll-outs, but RFC 9989, which replaced the original DMARC specification in May 2026, removed it and lists it as historic6. The example below leaves it out.
Google's suggested roll-out: start with p=none, read the reports, fix the senders that fail, and over time move to quarantine and then to reject3.
The three example records for example.com
This is the DNS zone for a domain that only sends through Google Workspace. The DKIM key is shortened: use the full one from the console.
example.com. 3600 IN TXT "v=spf1 include:_spf.google.com ~all"
google._domainkey.example.com. 3600 IN TXT "v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA" "(rest of the full key from the console)"
_dmarc.example.com. 3600 IN TXT "v=DMARC1; p=none; rua=mailto:dmarc@example.com"Two formatting details. A TXT record longer than 255 characters is written as several quoted strings within the same record, like the DKIM line; many DNS dashboards do this for you. And if your dashboard appends the domain automatically, type only google._domainkey or _dmarc in the host field3.
What does Gmail require from senders?
Since 1 February 2024, Gmail has requirements for anyone sending to personal accounts (those ending in @gmail.com or @googlemail.com)7:
- Requirement
- Authentication
- All senders
- SPF or DKIM
- More than 5,000 messages a day
- SPF and DKIM
- Requirement
- DMARC
- All senders
- Not required
- More than 5,000 messages a day
- Required;
p=noneis enough
- Requirement
From:aligned with SPF or DKIM- All senders
- Not required
- More than 5,000 messages a day
- Required
- Requirement
- Valid forward and reverse DNS (PTR)
- All senders
- Yes
- More than 5,000 messages a day
- Yes
- Requirement
- TLS connection
- All senders
- Yes
- More than 5,000 messages a day
- Yes
- Requirement
- Spam rate in Postmaster Tools
- All senders
- Below 0.3%
- More than 5,000 messages a day
- Below 0.3%; Google recommends under 0.1%
- Requirement
- One-click unsubscribe
- All senders
- Not required
- More than 5,000 messages a day
- Required for marketing and subscribed mail
Even if you send very little, Google recommends always setting up SPF, DKIM and DMARC7. With all three in place, your domain is much harder to spoof.
How to check it
- On a real message: send an email to a Gmail account that is not your own (Google warns you cannot verify DKIM by sending a message to yourself). In Gmail, next to Reply, click More > Show original. Under
Authentication-Resultsyou should seespf=pass,dkim=passanddmarc=pass2. - In DNS: the Google Admin Toolbox includes Check MX, which reviews the domain's MX and SPF records, and Dig, for looking up the TXT at
_dmarc.example.comorgoogle._domainkey.example.com. - In DMARC reports: with
p=none, Google describes them as a daily report sent to theruaaddress3. Any failing source you do not recognise is either a sender you left out of SPF or a spoofing attempt.
What SmoothSeen does with this
SmoothSeen queries the DNS of the domain you analyse and checks whether it has an SPF record and a DMARC record, and with which policy. It does not check DKIM: the public key lives at a name that depends on the selector (google._domainkey for Google Workspace, something else for every other provider), and without knowing the selector it cannot be looked up from outside. For DKIM, the proof is the header of a real message.
What to do this week
Look up the TXT records at the root of your domain and check there is exactly one SPF record covering all your senders. If DKIM is not showing "Authenticating", generate the key today and publish DMARC at p=none two days later. If you also want to see how the rest of your site is doing, analyse it with SmoothSeen.
Frequently asked questions
Can I have two SPF records if I use Google Workspace and Mailchimp?
No. A domain can only have one SPF record, and two records make the check fail with a permanent error. Put both services on a single line, with one include: for each: v=spf1 include:_spf.google.com include:servers.mcsv.net ~all. Keep an eye on the total number of DNS lookups so it does not exceed ten.
Should Google Workspace SPF end in ~all or -all?
Google recommends ~all, which asks receivers to flag mail from unlisted servers as suspicious. Microsoft recommends -all for its own domains, explaining that with ~all the DMARC policy has practically no effect on messages that fail SPF and carry no DKIM signature. If you follow Google's advice, make sure all your legitimate mail goes out DKIM-signed.
How long does DKIM take to work in Google Workspace?
There are two waits. After turning on Gmail for the organisation, 24 to 72 hours before you can generate the key. After publishing it in DNS, up to 48 hours for it to work. During that time the console may still say DNS records are missing even when they are published correctly; check with Dig and with a real message.
Do I need DMARC if I send fewer than 5,000 emails a day?
Gmail does not require it below that volume, but Google recommends setting it up regardless. Without DMARC, nothing tells receiving servers what to do with mail that spoofs your domain, and you get no reports showing who sends in your name. Starting at p=none does not affect delivery.
Sources
- 1Set up SPF, Google Workspace Admin Help, updated 7 October 2026.
- 2Set up DKIM, Google Workspace Admin Help, updated 7 October 2026.
- 3Set up DMARC, Google Workspace Admin Help, updated 7 October 2026.
- 4About SPF records, Google Workspace Admin Help, updated 7 October 2026.
- 5Set up SPF to identify valid email sources for your custom cloud domains, Microsoft Learn, updated 3 July 2026.
- 6RFC 9989: Domain-Based Message Authentication, Reporting, and Conformance (DMARC), IETF, May 2026.
- 7Email sender guidelines, Gmail Help, accessed 7 October 2026.
How to cite this article
SmoothSeen. (2026, October 7). Google Workspace SPF, DKIM and DMARC: the three DNS records step by step. https://smoothseen.com/en/blog/google-workspace-spf-dkim-dmarc/
Keep reading
What is SEO? How search engine optimisation works and how to improve it in 2026
What SEO is, how Google decides which pages to show and a prioritised checklist to improve your rankings with free tools.
.htaccess force HTTPS: redirect to https, enable HSTS and add security headers in Apache
How to force HTTPS in .htaccess or an Apache VirtualHost, roll out HSTS safely and add security headers. Every snippet tested on Apache 2.4.69.
.htaccess gzip and Brotli: browser caching and blocking AI bots in Apache
How to enable gzip and Brotli, set browser caching and block AI training bots in Apache .htaccess without dropping out of ChatGPT search. Tested.