Google Workspace: check SPF, DKIM and DMARC
Enable DKIM for your custom Workspace domain and check authentication across sending paths.
Administrator checklist
- Inventory Google Workspace and other services using your sending domain. Distinguish inbound and outbound mail, primary domains and additional sender domains.
- Check SPF with every legitimate sender and the DNS lookup limits. Another service does not justify a second SPF record.
- Generate a DKIM key for the specific domain in Google Admin. Publish its selector and TXT value at your DNS provider; prefer 2048 bits when supported.
- After publishing DNS, enable DKIM authentication in the Admin console. Key publication and active signing are separate steps.
- Check representative messages from each sending path for authentication and alignment. Add DMARC and review reports. Gmail recipient requirements and Workspace sender configuration are separate perspectives.
This guide covers sending configuration. It grants no tenant access and does not replace checking individual mail paths. Microsoft or Google sign-in proves neither domain ownership nor configuration.
Sources reviewed: 2026-09-10
Official source · Google Workspace