How to Set Up DMARC for Google Workspace
To set up DMARC for Google Workspace, publish an SPF record that includes _spf.google.com, turn on DKIM signing in the Admin console under Apps, Google Workspace, Gmail, Authenticate email, and then add a DMARC TXT record at _dmarc.yourdomain.com starting with p=none. This guide walks through each step and how to verify it.
By Stephen Williams · Updated
Before you start
- You need super administrator access to the Google Admin console and access to your domain's DNS.
- Gmail must be turned on for your organization. Google says to wait 24 to 72 hours after turning it on before generating a DKIM key.
- Make a list of any other services that send email as your domain (newsletters, CRM, help desk). They need their own SPF and DKIM setup; see below.
| Record | Type | Host / name | Value |
|---|---|---|---|
| SPF | TXT | @ (root domain) | v=spf1 include:_spf.google.com ~all |
| DKIM | TXT | google._domainkey | Generated in the Admin console (starts with v=DKIM1) |
| DMARC | TXT | _dmarc | v=DMARC1; p=none; rua=mailto:dmarc-reports@example.com |
Step 1: Publish the SPF record
If Google Workspace is the only service that sends email for your domain, add this TXT record at the root:
v=spf1 include:_spf.google.com ~allGoogle recommends ending the record with ~all. If other services send as your domain, add their include: entries to this same record. A domain must have only one SPF record, and evaluation is limited to 10 DNS lookups, so don't create a second v=spf1 record.
v=spf1 include:_spf.google.com include:sendgrid.net ~allThe SPF record generator builds this for you from a list of providers, and the SPF checker confirms it's valid and under the lookup limit.
Step 2: Turn on DKIM signing
DMARC only counts a DKIM signature whose signing domain (d=) aligns with your From address, so Google needs to sign mail with your own domain. In the Google Admin console:
- Go to Menu › Apps › Google Workspace › Gmail, then click Authenticate email.
- Select your domain and click Generate New Record.
- Choose a 2048-bit key if your DNS host supports it (use 1024 only if it doesn't), and keep the default selector prefix
google. - Click Generate, then copy the DNS host name (
google._domainkey) and the TXT record value. Don't click Start authentication yet. - At your DNS host, create a TXT record with that host name and value. Some DNS hosts limit TXT string length; a 2048-bit key may need to be split into multiple quoted strings within one record.
- Wait for the record to be published (Google says DKIM can take up to 48 hours to start working), then return to Authenticate email and click Start authentication. The status should change to "Authenticating email with DKIM".
Check the published key with the DKIM checker using the selector google.
Step 3: Publish the DMARC record
Google recommends allowing 48 hours after setting up SPF and DKIM before adding DMARC. There is nothing to configure in the Admin console; create the TXT record at your DNS host:
v=DMARC1; p=none; rua=mailto:dmarc-reports@example.comGoogle recommends always including rua and using a dedicated group or mailbox for the reports, since they arrive daily from every receiver. Start at p=none, review the reports in the DMARC report analyzer, then follow the DMARC policy rollout guide to move to quarantine and reject. You can also generate the record with the DMARC record generator.
Other services that send as your domain
Marketing platforms, CRMs and help desks that send mail with your domain in the From address need two things:
- Their
include:(or IP addresses) in your single SPF record, as shown above. - DKIM signing with your domain. Most platforms call this domain authentication and give you CNAME or TXT records to publish under their own selector. Without it, their mail may pass DKIM for the platform's domain but fail DMARC alignment for yours.
Verify everything passes
- Run the DMARC checker on your domain to confirm the record is published and valid.
- Send a message to a Gmail or Google Workspace account other than your own; Google notes you can't verify by emailing yourself.
- In Gmail, open the message, choose Show original, and check that SPF, DKIM and DMARC all show PASS, with DKIM signed by your domain.
Simplified example of a passing result
Authentication-Results: mx.google.com;
dkim=pass header.i=@example.com header.s=google;
spf=pass smtp.mailfrom=user@example.com;
dmarc=pass (p=NONE) header.from=example.comTroubleshooting
- DKIM record not found: some DNS hosts append your domain automatically, so entering
google._domainkey.example.comcreatesgoogle._domainkey.example.com.example.com. Enter justgoogle._domainkey. - SPF PermError: usually two SPF records or more than 10 DNS lookups. Merge into one record and remove unused includes.
- DMARC fails for a third-party tool: the tool is signing with its own domain. Enable custom DKIM (domain authentication) in that tool.
Sources
Frequently asked questions
Where do I add the DMARC record for Google Workspace?
At your DNS host (the registrar or DNS provider for your domain), not in the Google Admin console. Create a TXT record with the host name _dmarc and a value such as v=DMARC1; p=none; rua=mailto: followed by the mailbox that should receive reports.
What DKIM selector does Google Workspace use?
The default selector prefix is google, so the public key is published as a TXT record at google._domainkey.yourdomain.com. You can choose another prefix when generating the key, for example if google is already in use.
Should I use ~all or -all in my Google Workspace SPF record?
Google recommends ~all (softfail). Either way, DMARC treats an SPF result other than pass as a failure, so your DMARC policy is what decides how unauthenticated mail is handled.
How long until DKIM starts working?
Google notes it can take up to 48 hours after you publish the TXT record for DKIM authentication to start working, and recommends allowing 48 hours after setting up SPF and DKIM before you set up DMARC.