Step‑by‑Step DMARC Record Setup for Google Workspace
Setting up DMARC for Google Workspace can feel like wiring a new circuit: you need the right components, a clear diagram, and a safe way to test before you flip the switch. Below is a practical, hands‑on guide that walks you through every stage—from checking your existing DNS to fine‑tuning a policy that protects your brand without breaking legitimate mail flow.
Why DMARC Matters for Google Workspace
- Brand protection – DMARC tells receiving servers whether to trust emails that claim to come from your domain.
- Spam reduction – Properly configured DMARC reduces the chance that phishing attacks use your address.
- Inbox placement – ISPs reward domains with a solid DMARC record, improving deliverability for legitimate messages.
Think of DMARC as a security guard at the front desk: SPF shows the guard the employee badge, DKIM proves the employee’s signature, and DMARC tells the guard what to do when the badge or signature looks suspicious.
Prerequisites
| Item | Why It’s Needed |
|---|---|
| Access to your DNS provider console | You’ll add a TXT record. |
Existing SPF record (Google Workspace includes v=spf1 include:_spf.google.com ~all) |
DMARC references SPF. |
| DKIM signing enabled in Google Admin console | DMARC also references DKIM. |
A mailbox to receive DMARC reports (e.g., [email protected]) |
Reports help you fine‑tune the policy. |
Tip: If you’re unsure whether SPF/DKIM are already live, run a quick lookup with The Network Tools DNS checker – it’s a fast way to verify existing records before you add DMARC.
1. Verify SPF and DKIM First
1.1 Check SPF
dig txt yourdomain.com +short
You should see something like:
v=spf1 include:_spf.google.com ~all
If SPF is missing, add it now; DMARC will ignore a domain without a valid SPF.
1.2 Enable DKIM in Google Workspace
- Sign in to admin.google.com.
- Navigate to Apps → Google Workspace → Gmail → Authenticate email.
- Click Generate new record, leave the default selector (
google) and click Generate. - Copy the generated TXT value and add it to your DNS as
google._domainkey.yourdomain.com.
After propagation (usually < 30 min), verify with:
dig txt google._domainkey.yourdomain.com +short
You should see a long string beginning with v=DKIM1; k=rsa; p=.
2. Draft Your DMARC Policy
A DMARC record is a single TXT entry placed at _dmarc.yourdomain.com. The record consists of tags that define how receivers should handle failing messages and where to send reports.
2.1 Choose a Policy Level
Policy (p=) |
Effect |
|---|---|
none |
No enforcement; only reporting. Great for the testing phase. |
quarantine |
Suspect messages go to spam/junk. |
reject |
Invalid mail is outright rejected. |
Best practice: Start with p=none for 1–2 weeks, review reports, then move to quarantine and finally reject.
2.2 Assemble the Record
Here’s a starter DMARC record for a Google Workspace domain:
v=DMARC1; p=none; rua=mailto:[email protected]; ruf=mailto:[email protected]; sp=none; aspf=r; adkim=r; pct=100
| Tag | Meaning |
|---|---|
v=DMARC1 |
Version (required). |
p=none |
Policy for the main domain. |
rua= |
Aggregate report URI (mailto). |
ruf= |
Forensic report URI (optional, many providers ignore). |
sp= |
Sub‑domain policy (mirrors p= if omitted). |
aspf=r |
SPF alignment mode (r = relaxed). |
adkim=r |
DKIM alignment mode (r = relaxed). |
pct=100 |
Apply policy to 100 % of messages. |
3. Add the DMARC TXT Record
3.1 Locate the DNS Management Area
Every provider looks a little different, but the steps are similar:
- Log into your DNS host (e.g., Cloudflare, GoDaddy, Route 53).
- Find Add Record → TXT.
- Host/Name:
_dmarc(some consoles require the full name_dmarc.yourdomain.com). - Value: paste the DMARC string from step 2.2.
- TTL: set to 1 hour (or the provider’s minimum).
3.2 Save and Propagate
Propagation can take anywhere from a few minutes to 24 hours, depending on TTL. Use The Network Tools DMARC lookup tool to confirm the record is visible:
https://www.thenetworktools.com/dmarc-lookup
Enter your domain; the tool will display the exact TXT value it sees.
4. Monitor Reports and Adjust
4.1 Collect Aggregate Reports
DMARC reports arrive as compressed XML files (usually daily). They contain:
- Source IPs that sent mail claiming your domain.
- Alignment results for SPF and DKIM.
- Disposition (
none,quarantine,reject).
You can parse them manually, but a dedicated parser (e.g., DMARCian, Postmark DMARC) makes the job painless.
4.2 Analyze the Data
Look for:
- Legitimate sources that are failing alignment (e.g., a marketing platform not using your domain’s SPF).
- Unknown IPs that may be spoofing your address.
If you spot legitimate senders failing, add them to your SPF record or configure DKIM for that service.
4.3 Tighten the Policy
Once you’re confident that only authorized sources pass SPF/DKIM:
- Change
p=none→p=quarantine. - Wait another week, review reports for any spikes in quarantine.
- If everything looks clean, switch to
p=reject.
5. Common Pitfalls & How to Avoid Them
| Pitfall | Symptom | Fix |
|---|---|---|
| Missing SPF | DMARC reports show “SPF alignment fail” for all mail. | Add a correct SPF record before DMARC. |
| DKIM selector mismatch | Reports list “DKIM alignment fail” even though DKIM is enabled. | Verify the selector (google) matches the DNS TXT you created. |
| Incorrect DNS host name | Lookup returns “No DMARC record found”. | Ensure the TXT is at _dmarc.yourdomain.com, not just dmarc. |
| Report mailbox not reachable | No reports arrive. | Create the mailbox, enable forwarding, and double‑check the rua= address. |
Too strict alignment (aspf=s/adkim=s) |
Legitimate third‑party mail gets rejected. | Use relaxed alignment (r) during the testing phase. |
6. Using The Network Tools for a Smooth Setup
While you can run dig or nslookup from the command line, The Network Tools offers a one‑stop dashboard:
- DNS TXT Checker – instantly verifies SPF, DKIM, and DMARC entries.
- DMARC Report Viewer – upload your XML files for a visual breakdown.
- Propagation Tracker – see how long your new DMARC record takes to appear worldwide.
A quick check after each change saves you from “wait‑and‑see” headaches.
7. Quick Reference Cheat Sheet
| Step | Action | Example |
|---|---|---|
| 1 | Verify SPF | dig txt yourdomain.com |
| 2 | Enable DKIM in Google Admin | google._domainkey.yourdomain.com |
| 3 | Draft DMARC (start with none) |
v=DMARC1; p=none; rua=mailto:[email protected]; aspf=r; adkim=r; pct=100 |
| 4 | Add TXT at _dmarc |
Host: _dmarcValue: above string |
| 5 | Confirm with DNS tool | Use The Network Tools DMARC lookup |
| 6 | Review reports for 7‑14 days | Adjust SPF/DKIM as needed |
| 7 | Move to quarantine → reject |
Update p= tag accordingly |
Conclusion
A well‑implemented DMARC record is the final piece of the email authentication puzzle for Google Workspace. By following this step‑by‑step guide, you’ll protect your brand, improve deliverability, and gain visibility into who’s sending mail on your behalf. Remember: start with a “listen‑only” policy, let the data speak, then tighten enforcement. And whenever you need a quick sanity check, The Network Tools is ready to verify your DNS changes in seconds.
Secure your inbox today—your customers (and your reputation) will thank you.
You might also need
Keep troubleshooting with these related free tools.