Gmail / Google Workspace: SPF, DKIM & DMARC Setup Guide
Gmail powers billions of inboxes. If your SPF, DKIM, or DMARC isn't set up correctly for Google Workspace, your emails will land in spam — or bounce entirely. Here's exactly what to configure.
1SPF Record Setup
Recommended SPF record for Gmail:
v=spf1 include:_spf.google.com ~allGoogle's SPF include covers all Google Workspace sending servers across all regions. Do not add individual Google IP ranges — they change frequently. Use the include mechanism only.
Step-by-step setup:
- 1Log in to your domain registrar or DNS provider
- 2Go to DNS settings and find existing TXT records for your root domain (@)
- 3If an SPF record exists, add include:_spf.google.com to it (only one SPF record allowed per domain)
- 4If no SPF record exists, create a new TXT record: v=spf1 include:_spf.google.com ~all
- 5Wait 24–48 hours for DNS propagation
- 6Verify with our SPF checker tool
2DKIM Setup
Example DKIM record location:
google._domainkey.yourdomain.comGoogle Workspace generates a 2048-bit RSA key pair. The selector is always 'google' for the default key, but you can generate additional keys with custom selectors.
Step-by-step setup:
- 1In Google Admin Console, go to Apps → Google Workspace → Gmail → Authenticate email
- 2Select your domain and click Generate new record
- 3Choose 2048-bit key length (recommended)
- 4Copy the TXT record value and add it to your DNS as: google._domainkey.yourdomain.com
- 5Return to Admin Console and click Start authentication
- 6Allow 24–48 hours, then verify with our DKIM checker
3DMARC Policy
Recommended DMARC record:
v=DMARC1; p=quarantine; rua=mailto:dmarc@yourdomain.com; pct=100Add as a TXT record at: _dmarc.yourdomain.com
Google requires a DMARC policy of at least p=none for bulk senders sending over 5,000 emails/day. Moving to p=quarantine or p=reject provides full protection against spoofing.
Common Gmail Deliverability Issues
Emails going to spam despite correct SPF/DKIM
Check that DMARC is configured and that the From: header domain matches your SPF/DKIM domain (alignment). Also verify your domain isn't on any blacklists.
DKIM signature failing
Ensure the TXT record value is published correctly — it's often very long and may need to be split across multiple strings. Verify in Google Admin Console that authentication is active, not just generated.
Multiple SPF records causing failures
You can only have one SPF record per domain. Merge all includes into a single record: v=spf1 include:_spf.google.com include:otherprovider.com ~all
Google Postmaster Tools showing high spam rate
Check your sending lists for stale or purchased addresses. Review complaint rates by IP and domain. Implement DMARC rua reporting to identify unauthorized senders.
Is Your Gmail Domain Blacklisted?
Authentication passing is necessary — but not sufficient. Check if your sending domain or IP is on any of 60 blacklists. Free, instant, no signup.
Check Your Domain FreeChecks all 60 blacklists + SPF, DKIM, DMARC, MX in under 10 seconds