Dmarc Overview

Set up DMARC with Google Workspace

This guide shows what to configure for a domain whose mail is sent from Google Workspace and how to confirm it in DMARC+. For the exact steps in Google's admin console, use Google's documentation, since screens change. Search for "Google Workspace SPF", "Google Workspace DKIM" and "Google Workspace DMARC".

What you need to configure

Record Requirement Where the details come from
SPF One SPF record that includes Google's sending servers Google's SPF documentation gives the include value
DKIM Generate a domain key and publish it, then start signing Google's DKIM documentation. The default selector is shown when you generate the key.
DMARC A record at _dmarc.<domain> with your DMARC+ report address DMARC+ Managed DMARC or the DMARC Generator

Note: Google does not sign with your domain until you generate and enable a key for it. Without it, DMARC can only pass through SPF.

Steps

  1. Add the domain in DMARC+ and set the DKIM selector to the one Google shows for the key.
  2. Set up SPF with Google's include. Keep other senders in the same record. Check with Tools > SPF.
  3. Generate and publish the DKIM key following Google's documentation. Confirm the record in Tools > DKIM.
  4. Start signing, then confirm signing is active by looking at DKIM results in the Aggregate Reports Explorer after a day or two.
  5. Publish DMARC at **p=none**. See Set up DMARC for the first time.
  6. Review two weeks of data, fix senders and continue with From monitoring to enforcement.

Things to check for Google Workspace

Check Why
A key is generated for every sending domain Each domain and alias domain needs its own
Long DKIM values are entered correctly at your DNS host Some hosts need the value split, or reject line breaks
Groups and mailing lists Messages sent on behalf of a group can change the sender path
Other services that send through Google Relays and applications may use different paths

Reading the results

Symptom Likely cause Fix
Google mail passes SPF but fails DMARC DKIM not enabled for your domain Generate and enable the key
DKIM fails Key not published, or wrong selector Check with the DKIM tool
SPF too many lookups Too many includes See What is SPF?
Mail from a group fails Rewritten sender or forwarding See Troubleshooting

Before enforcing

  • Every Google path passes DMARC in the Aggregate Reports.
  • Other services that send as your domain are covered. See Managing third-party senders.