If your business uses Gmail through Google Workspace, three DNS records decide whether your email reaches the inbox or the spam folder: SPF, DKIM and DMARC. This guide walks you through all three, in order, with the exact values to copy.
Time needed: about 20 minutes of work, plus waiting time for DNS changes (usually under an hour, occasionally up to 48 hours).
Before you start, you’ll need two logins:
- The Google Admin console (admin.google.com) as a super administrator.
- The company that manages your domain’s DNS. This is often where you bought the domain (GoDaddy, Squarespace, Namecheap) or a service like Cloudflare. Not sure? Our free check shows your current records.
Why this matters now
Since 2024, Gmail and Yahoo have required senders to prove their email is genuine, and Microsoft has followed. Businesses that send in volume must have all three records; everyone else is judged more harshly without them. A missing or broken record is one of the most common reasons invoices, quotes and replies quietly land in spam.
| Record | What it does | You set it up in |
|---|---|---|
| SPF | Lists the servers allowed to send email for your domain | Your DNS host |
| DKIM | Adds a digital signature proving your email wasn’t forged or changed | Google Admin console, then your DNS host |
| DMARC | Tells receivers what to do with email that fails SPF and DKIM, which stops others from spoofing you | Your DNS host |
Step 1: Add your SPF record
First, look at your existing DNS records for a TXT record that starts with v=spf1. A domain can only have one SPF record. If one already exists, edit it instead of adding a second, because two SPF records cancel each other out.
If you only send email through Google Workspace, add this TXT record:
| Type | TXT |
|---|---|
| Host / Name | @ (some hosts want your domain name, like yourcompany.com) |
| Value | v=spf1 include:_spf.google.com ~all |
Do other services send email as your domain? Newsletters, CRMs, invoicing and help desk tools often do. Add each one’s include: to the same record, before ~all. For example, Google Workspace plus Microsoft 365:
v=spf1 include:_spf.google.com include:spf.protection.outlook.com ~all
Each service tells you its include value in its own setup instructions. Keep the total under 10 DNS lookups; past that, SPF fails for every email. The free check counts them for you.
Step 2: Turn on DKIM signing
DKIM is a two-part job: Google creates a key, you publish it in DNS, then you tell Google to start signing.
Create the key in Google
- Sign in to admin.google.com.
- Go to Menu → Apps → Google Workspace → Gmail → Authenticate email.
- Choose your domain under Selected domain, then click Generate new record.
- Choose 2048 for key length and leave the prefix selector as google. Click Generate.
- Google shows a DNS Host name (
google._domainkey) and a long TXT record value starting withv=DKIM1. Keep this page open.
Publish it in DNS
At your DNS host, add a new TXT record:
| Type | TXT |
|---|---|
| Host / Name | google._domainkey |
| Value | The full value Google gave you, starting with v=DKIM1; k=rsa; p= |
Two common mistakes: Enter only google._domainkey as the host; most DNS hosts add your domain automatically, so typing google._domainkey.yourcompany.com creates a broken record. And copy the whole value; it’s long. If your DNS host rejects it as too long, generate a 1024-bit key in Google instead.
Start signing
Back in the Admin console on the same Authenticate email page, click Start authentication. If Google says it can’t find the record yet, wait an hour and try again; new DNS records can take up to 48 hours to appear everywhere. When it works, the status reads Authenticating email with DKIM.
Step 3: Add DMARC, then tighten it
Google recommends having SPF and DKIM working for at least 48 hours before adding DMARC. Start in monitor-only mode, so nothing gets blocked while you confirm everything passes:
| Type | TXT |
|---|---|
| Host / Name | _dmarc |
| Value | v=DMARC1; p=none; rua=mailto:[email protected] |
Replace [email protected] with a mailbox or group you’ll check. Mail providers send daily reports there showing every server that sent email using your name. A dedicated address or Google Group keeps them out of your main inbox.
Monitor mode alone doesn’t stop spoofing. Once the reports show your real email passing for at least a week, tighten the policy in steps:
| Stage | DMARC value | What happens |
|---|---|---|
| 1. Monitor (1+ week) | v=DMARC1; p=none; rua=mailto:[email protected] | Nothing is blocked; you collect reports |
| 2. Quarantine a share | v=DMARC1; p=quarantine; pct=10; rua=mailto:[email protected] | 10% of failing email goes to spam; raise pct over a few weeks |
| 3. Reject | v=DMARC1; p=reject; rua=mailto:[email protected] | Forged email using your domain is refused |
Step 4: Check that it worked
- Run your domain through the free MailWatchman check. SPF, DKIM and DMARC should all show as passed (DMARC shows “needs attention” while it’s at
p=none, which is expected at first). - Send an email from your Workspace account to a personal Gmail address. Open it, click the three dots, and choose Show original. You should see PASS next to SPF, DKIM and DMARC.
Common problems and fixes
| Problem | Fix |
|---|---|
| Two SPF records | Merge every include: into one record and delete the other. |
| SPF over 10 lookups | Remove includes for tools you no longer use. |
| DKIM shows “not found” | Check the host is exactly google._domainkey, the value was copied in full, and wait up to 48 hours. |
| Newsletter or invoices still go to spam | That tool sends on its own servers. Add its SPF include, and turn on DKIM in that tool too. |
DMARC stuck at p=none | It protects nothing at this setting. Move through the stages above once reports are clean. |
These records can break without warning
A website change, a new email tool or a DNS update can quietly undo this work. MailWatchman checks your domain every day and emails you the moment something changes, with the fix. Plans start at $6 a month.
Based on Google’s own instructions for SPF, DKIM and its recommended DMARC rollout. Google occasionally renames menus; if a step looks different, the record values above stay the same.