Google Workspace SPF, DKIM and DMARC check
Enter the domain you send from with Google Workspace. We check the SPF include, the Google Workspace DKIM key, your DMARC policy and MX records, and tell you what is missing.
What Google Workspace expects
SPF
Add include:_spf.google.com to your single SPF record, for example: v=spf1 include:_spf.google.com ~all
Costs 1 of your 10 SPF lookups (checked October 2026).
Build a combined SPF record if you send from more than one service.
DKIM
Selector we look for: google
Generate the key in the Admin console under Apps > Google Workspace > Gmail > Authenticate email, publish the TXT record, then click "Start authentication". The default selector is "google". Choose a 2048-bit key if your DNS host allows it.
DMARC
DMARC is set on your domain, not in Google Workspace. If you have none, start with v=DMARC1; p=none; rua=mailto:dmarc@yourdomain.com and tighten it once reports look clean. Generate one.
MX
smtp.google.com (priority 1). Older setups use aspmx.l.google.com plus alt1 to alt4.
Values come from Google Workspace’s public setup documentation and can change. The Admin console always shows the exact records for your account. Use those if they differ from this page.
Keep it working after setup
The usual failures come later: a second SPF record added for a new tool, a DKIM CNAME lost in a DNS move, a DMARC record deleted with an old zone. SenderBeacon checks twice a day and emails you in plain English. From $9/month, 14-day free trial, no card.
Start free trialQuestions
How long until Google Workspace DNS changes show up?
Usually minutes, sometimes up to an hour, depending on the TTL on your records and your DNS host. Re-run the check after publishing.
Why does the check say DKIM is missing when Google Workspace says it is verified?
Most often the record went on the wrong host (for example _domainkey.yourdomain.com.yourdomain.com, because the DNS host appended the domain twice), or you are checking a different domain or subdomain than the one you send from.