If your business email runs on Google Workspace, three DNS records decide whether your mail reaches inboxes and whether anyone can send email pretending to be you: SPF, DKIM and DMARC. Gmail and Yahoo have required them from bulk senders since 2024, and missing them is one of the most common reasons ordinary business email lands in spam.
This guide sets up all three. It takes about 20 minutes, plus waiting time for DNS. You need admin access to Google Workspace and to wherever your domain's DNS is managed (Cloudflare, GoDaddy, Namecheap, your web host and so on).
Not sure what you have today? Check your domain with our free DMARC checker first. It shows which of the three records exist and what's wrong with them.
Step 1: SPF, the list of servers allowed to send for you
SPF is a TXT record on your domain itself (host @) that lists the services allowed to send email as your domain.
- Open your DNS provider and look for an existing TXT record that starts with
v=spf1. A domain must have only one. If you already have one, edit it instead of adding a second. - If you only send email through Google Workspace, the record is:
v=spf1 include:_spf.google.com ~all - If other services also send as your domain (a newsletter tool, your CRM, your website's contact form, Amazon SES), add their
include:to the same record, for example:v=spf1 include:_spf.google.com include:amazonses.com ~all
Keep it under 10 DNS lookups in total; every include: counts, including the ones inside it. Past 10, SPF fails for every message.
Step 2: DKIM, a signature that proves the email is really from you
DKIM adds a cryptographic signature to each message. Google generates the key; you publish it in DNS.
- In the Google Admin console, go to Apps → Google Workspace → Gmail → Authenticate email.
- Select your domain and click Generate new record. Choose a 2048-bit key if your DNS provider allows long TXT records; otherwise 1024-bit.
- Google shows a DNS host name (usually
google._domainkey) and a long TXT record value starting withv=DKIM1. Add that TXT record at your DNS provider. - Wait until the record is live (often minutes, sometimes up to 48 hours), then go back to the Admin console and click Start authentication.
If you skip the last click, the record sits in DNS but Gmail never signs your mail with it.
Step 3: DMARC, what receivers should do when a check fails
SPF and DKIM only produce a pass or fail. DMARC tells receiving servers what to do with mail that fails, and sends you reports about who is sending as your domain.
- Add a TXT record with the host
_dmarc. - Start in monitoring mode:
v=DMARC1; p=none; rua=mailto:dmarc@yourdomain.com; fo=1 - Make sure the
ruaaddress exists. Google, Microsoft and Yahoo will send it a daily XML report.
Then tighten it
After two to four weeks, the reports show every service sending as your domain. Once everything legitimate passes, change p=none to p=quarantine (failing mail goes to spam), and later to p=reject (failing mail is refused). That's the point where nobody can spoof your domain any more.
Step 4: Check that it works
- Run your domain through the DMARC checker again. SPF and DMARC should pass, and DKIM should be found under the
googleselector. - Send an email from your Workspace account to a personal Gmail address, open it, and choose ⋮ → Show original. You want SPF: PASS, DKIM: PASS and DMARC: PASS.
Common mistakes
- Two SPF records. Merge them into one; with two, SPF fails for everything.
- Forgetting other senders. Newsletter tools and contact forms that send as your domain fail DMARC once you move to quarantine, unless they're in SPF or sign with DKIM for your domain.
- Jumping straight to
p=reject. Start withp=noneand read the reports first. - Setting it and forgetting it. Records get deleted when DNS is moved or a new service is added. Daily Website Report re-checks your email records every day and tells you when something changes.