This guide shows what to configure for a domain whose mail is sent from Google Workspace and how to confirm it in DMARC+. For the exact steps in Google's admin console, use Google's documentation, since screens change. Search for "Google Workspace SPF", "Google Workspace DKIM" and "Google Workspace DMARC".
What you need to configure
Record
Requirement
Where the details come from
SPF
One SPF record that includes Google's sending servers
Google's SPF documentation gives the include value
DKIM
Generate a domain key and publish it, then start signing
Google's DKIM documentation. The default selector is shown when you generate the key.
DMARC
A record at _dmarc.<domain> with your DMARC+ report address
DMARC+ Managed DMARC or the DMARC Generator
Note: Google does not sign with your domain until you generate and enable a key for it. Without it, DMARC can only pass through SPF.
Steps
Add the domain in DMARC+ and set the DKIM selector to the one Google shows for the key.
Set up SPF with Google's include. Keep other senders in the same record. Check with Tools > SPF.
Generate and publish the DKIM key following Google's documentation. Confirm the record in Tools > DKIM.
Start signing, then confirm signing is active by looking at DKIM results in the Aggregate Reports Explorer after a day or two.