If your business email runs on Google Workspace, three DNS records decide whether your mail reaches inboxes and whether anyone can send email pretending to be you: SPF, DKIM and DMARC. Gmail and Yahoo have required them from bulk senders since 2024, and missing them is one of the most common reasons ordinary business email lands in spam.

This guide sets up all three. It takes about 20 minutes, plus waiting time for DNS. You need admin access to Google Workspace and to wherever your domain's DNS is managed (Cloudflare, GoDaddy, Namecheap, your web host and so on).

Not sure what you have today? Check your domain with our free DMARC checker first. It shows which of the three records exist and what's wrong with them.

Step 1: SPF, the list of servers allowed to send for you

SPF is a TXT record on your domain itself (host @) that lists the services allowed to send email as your domain.

  1. Open your DNS provider and look for an existing TXT record that starts with v=spf1. A domain must have only one. If you already have one, edit it instead of adding a second.
  2. If you only send email through Google Workspace, the record is:
    v=spf1 include:_spf.google.com ~all
  3. If other services also send as your domain (a newsletter tool, your CRM, your website's contact form, Amazon SES), add their include: to the same record, for example:
    v=spf1 include:_spf.google.com include:amazonses.com ~all

Keep it under 10 DNS lookups in total; every include: counts, including the ones inside it. Past 10, SPF fails for every message.

Step 2: DKIM, a signature that proves the email is really from you

DKIM adds a cryptographic signature to each message. Google generates the key; you publish it in DNS.

  1. In the Google Admin console, go to Apps → Google Workspace → Gmail → Authenticate email.
  2. Select your domain and click Generate new record. Choose a 2048-bit key if your DNS provider allows long TXT records; otherwise 1024-bit.
  3. Google shows a DNS host name (usually google._domainkey) and a long TXT record value starting with v=DKIM1. Add that TXT record at your DNS provider.
  4. Wait until the record is live (often minutes, sometimes up to 48 hours), then go back to the Admin console and click Start authentication.

If you skip the last click, the record sits in DNS but Gmail never signs your mail with it.

Step 3: DMARC, what receivers should do when a check fails

SPF and DKIM only produce a pass or fail. DMARC tells receiving servers what to do with mail that fails, and sends you reports about who is sending as your domain.

  1. Add a TXT record with the host _dmarc.
  2. Start in monitoring mode:
    v=DMARC1; p=none; rua=mailto:dmarc@yourdomain.com; fo=1
  3. Make sure the rua address exists. Google, Microsoft and Yahoo will send it a daily XML report.

Then tighten it

After two to four weeks, the reports show every service sending as your domain. Once everything legitimate passes, change p=none to p=quarantine (failing mail goes to spam), and later to p=reject (failing mail is refused). That's the point where nobody can spoof your domain any more.

Step 4: Check that it works

  • Run your domain through the DMARC checker again. SPF and DMARC should pass, and DKIM should be found under the google selector.
  • Send an email from your Workspace account to a personal Gmail address, open it, and choose ⋮ → Show original. You want SPF: PASS, DKIM: PASS and DMARC: PASS.

Common mistakes

  • Two SPF records. Merge them into one; with two, SPF fails for everything.
  • Forgetting other senders. Newsletter tools and contact forms that send as your domain fail DMARC once you move to quarantine, unless they're in SPF or sign with DKIM for your domain.
  • Jumping straight to p=reject. Start with p=none and read the reports first.
  • Setting it and forgetting it. Records get deleted when DNS is moved or a new service is added. Daily Website Report re-checks your email records every day and tells you when something changes.