Google Workspace guide
SPF, DKIM and DMARC for Google Workspace: exact records
The exact SPF, DKIM and DMARC records for Google Workspace, how to generate the DKIM key in the Admin console, and the mistakes that break DMARC.
DMARC Done team · 5 October 2026 · 5 min read
This guide is for businesses that use Gmail through Google Workspace with their own domain. It covers the three records Google asks for, in the order to add them, using the values from Google’s own help pages.
Google generates the DKIM key for you in the Admin console. Everything else, and the DKIM key itself, is published at your DNS host: the company where your domain’s DNS records live.
The records at a glance
| Record | Type | Host | Value |
|---|---|---|---|
| SPF | TXT | @ |
v=spf1 include:_spf.google.com ~all |
| DKIM | TXT | google._domainkey |
generated in the Admin console |
| DMARC | TXT | _dmarc |
v=DMARC1; p=none; rua=mailto:dmarc-reports@yourdomain.com; fo=1 |
SPF: one TXT record at the root
SPF (Sender Policy Framework) lists the servers allowed to send mail for your domain. If Google Workspace is the only service that sends mail as you, use Google’s record:
Type: TXT
Host: @
Value: v=spf1 include:_spf.google.com ~all
Google states: “Google recommends you use ~all in your SPF record.” That is a soft fail: mail from unlisted servers is marked as suspicious rather than refused outright. Once DMARC is enforced, DMARC decides what happens to failing mail anyway.
If other services send as your domain too, such as a newsletter tool or a helpdesk, add their include: values before ~all in the same record. A domain can have only one SPF record.
Google says it can take up to 48 hours for SPF to start working.
DKIM: generate the key, publish it, then start
DKIM (DomainKeys Identified Mail) signs every message with a key tied to your domain. Until you set it up, Gmail does not sign your mail in a way that DMARC can match to your domain.
Step 1: Generate the key
- Sign in to the Google Admin console with an administrator account.
- Go to Menu > Apps > Google Workspace > Gmail > Authenticate email.
- Select your domain and choose to generate a new record.
- Pick the key length. Google’s advice: choose 2048 if your domain provider supports 2048-bit keys, otherwise 1024.
- Leave the prefix selector as the default,
google, unless you already use that name.
If you only just turned on Gmail for your domain, Google says you may need to wait 24 to 72 hours before you can generate the key.
Step 2: Publish it at your DNS host
Google shows a TXT record name and a long value starting with v=DKIM1. Add it exactly:
Type: TXT
Host: google._domainkey
Value: v=DKIM1; k=rsa; p=MIIBIjANBgkq... (copy the full value from Google)
Step 3: Start authentication
Back on the Authenticate email page, click Start authentication. The status should change to say Gmail is authenticating email with DKIM. Google says it can take up to 48 hours for DKIM to start working after you add the record.
DMARC: one TXT record at _dmarc
DMARC (Domain-based Message Authentication, Reporting and Conformance) tells receivers what to do with mail that fails SPF and DKIM, and sends you reports. Google’s guidance is to start with the policy set to none, and to allow 48 hours after setting up SPF and DKIM before you set up DMARC.
Type: TXT
Host: _dmarc
Value: v=DMARC1; p=none; rua=mailto:dmarc-reports@yourdomain.com; fo=1
Create the dmarc-reports@ address first, as a user, group or alias, so reports are not bounced. Reports arrive as daily XML attachments, so a Google Group works better than a person’s inbox.
Note that Google’s DMARC help page shows a finished, strict record as its example (p=reject with strict alignment). That is where you end up, not where you start.
Plain-English takeaway: For Google Workspace, publish one SPF record with
include:_spf.google.com ~all, generate a DKIM key in the Admin console and publish it atgoogle._domainkey, click Start authentication, then add DMARC at_dmarcwithp=none.
Where to add the records
All three records go in your DNS host’s control panel:
- Sign in at your DNS host and open the DNS settings for your domain.
- Add each record with the type, host and value above.
- Save. For DKIM, go back to the Admin console and click Start authentication.
Panels differ in how they want the host name typed. Some want _dmarc, some accept _dmarc.yourdomain.com. Our guides for GoDaddy, Cloudflare, IONOS, Strato and Namecheap cover each one.
Common mistakes
- Generating the key but not clicking Start authentication. The record is in DNS, but Gmail is not signing yet. Your mail still fails DKIM alignment.
- A truncated DKIM key. The 2048-bit value is long. If your DNS panel cuts it short, DKIM fails. Some panels need the value split into several quoted strings. If yours will not accept it, generate a 1024-bit key instead, as Google suggests.
- Two SPF records. If you moved from another email host, its SPF record may still be there. Merge everything into one record.
- Forgetting other senders. Mail sent “from” your domain by a CRM, newsletter tool or website form does not go through Gmail. Each one needs its own SPF or DKIM setup with your domain before you enforce DMARC.
- Adding DMARC before checking reports exist. Without a working
ruamailbox, you will have no data when it is time to enforce.
Gmail’s own rules for senders
Since February 1, 2024, Google requires every sender to Gmail accounts to set up SPF or DKIM. Senders of more than 5,000 messages a day to Gmail accounts must have SPF, DKIM and a DMARC record, though the DMARC policy “can be set to none.” Following this guide meets those requirements for your Workspace mail.
Check your setup
Run the free checker at /check?d=yourdomain.com. It detects Google Workspace, checks SPF, the google DKIM selector and DMARC, and shows anything that is missing.
When to move to quarantine and reject
p=none collects reports but does not stop anyone from sending email as your domain. Google’s guidance is to move to quarantine and then reject once reports show your legitimate mail passes. Our post on DMARC quarantine vs reject explains the order and how long to wait.
If you want us to read the reports, fix the senders and take the domain to p=reject, see pricing. If we do not get there within 60 days, you get a full refund.
Sources
- Google Workspace Admin Help, Set up SPF: https://knowledge.workspace.google.com/admin/security/set-up-spf
- Google Workspace Admin Help, Set up DKIM: https://knowledge.workspace.google.com/admin/security/set-up-dkim
- Google Workspace Admin Help, Set up DMARC: https://knowledge.workspace.google.com/admin/security/set-up-dmarc
- Gmail Help, Email sender guidelines: https://support.google.com/mail/answer/81126