Thursday, September 24, 2026

Set Up DMARC for Google Workspace Email


How to Set Up DMARC for Google Workspace:
Stop Email Spoofing for Good!

If you own a custom domain, email security isn't optional anymore. Major email providers like Google, Yahoo, and Microsoft strictly require authentication records to ensure your emails reach the inbox instead of the spam folder.

Setting up DMARC (Domain-based Message Authentication, Reporting, and Conformance) prevents scammers from impersonating your business while boosting your overall email deliverability.

Here is a step-by-step guide to properly setting up DMARC alongside SPF and DKIM.


The Email Security Trinity Explained

Before touching DNS settings, it helps to understand how the three main authentication tools work together:

  1. SPF (Sender Policy Framework): A public list in your DNS of every server or service allowed to send email from your domain.

  2. DKIM (DomainKeys Identified Mail): A digital signature attached to outgoing emails proving the message wasn't tampered with in transit.

  3. DMARC: The instructions you give receiving servers on what to do if an email fails SPF or DKIM alignment (e.g., monitor, spam-folder, or reject completely).


Step 1: Verify Your SPF and DKIM Records First

DMARC requires at least one of the other two protocols (SPF or DKIM) to be active and passing. For full security, set up both.

Check Your SPF Record

Log in to your DNS host (e.g., GoDaddy, Cloudflare, Namecheap) and ensure you have a TXT record pointing to your mail provider.

  • Host/Name: @ (or leave blank depending on your registrar)

  • Value for Google Workspace: v=spf1 include:_spf.google.com ~all

Generate Your DKIM Key

  1. Log in to your Google Admin Console (admin.google.com).

  2. Go to Apps > Google Workspace > Gmail > Authenticate email.

  3. Click Generate New Record and copy the resulting Host Name (usually google._domainkey) and the long string of text.

  4. Add a new TXT record in your DNS provider using those values.

Crucial Step: Once the TXT record is saved in your DNS, return to Google Admin Console and click Start Authentication. Google will not sign your emails until this button is activated.


Step 2: Add Your DMARC Record

Navigate to your DNS host's management page and add a new TXT record with the following details:

  • Type: TXT

  • Name / Host: _dmarc (Common Trap: Enter ONLY _dmarc. Many DNS providers automatically append your domain name. Typing _dmarc.yourdomain.com will break the record.)

  • Value / Text: v=DMARC1; p=quarantine; pct=25; rua=mailto:dmarc-reports@yourdomain.com (Replace the email address with where you'd like to receive daily XML delivery reports.)

  • TTL: 1 Hour or Auto


Step 3: Understand the Phased DMARC Rollout Strategy

Flipping DMARC straight to maximum protection (p=reject) can accidentally block legitimate outgoing emails if a third-party service (like Mailchimp, QuickBooks, or a web form) isn't authenticated yet.

Use a phased approach to safely ramp up enforcement:

Phase 1: Monitoring Mode (p=none)

  • Record Value: v=DMARC1; p=none; rua=mailto:you@yourdomain.com

  • What it does: Collects delivery reports without altering email delivery.

  • Duration: Run for 1–2 weeks to verify all valid sending sources are identified.

Phase 2: Gradual Quarantine (p=quarantine with pct)

  • Record Value: v=DMARC1; p=quarantine; pct=25; rua=mailto:you@yourdomain.com

  • What it does: Applies spam protection to 25% of failing emails while passing the other 75% for testing.

  • Next Steps: Slowly increase pct=25 to pct=50 to pct=100 over a few weeks.

Phase 3: Total Enforcement (p=reject)

  • Record Value: v=DMARC1; p=reject; rua=mailto:you@yourdomain.com

  • What it does: Receiving servers will flat-out drop/block any email failing authentication before it ever touches a user's inbox.

  • Goal: Maximum defense against domain spoofing and phishing attacks.


Step 4: Test and Verify Your Setup

Once all records are saved and propagation has finished (usually 15–30 minutes):

  1. Send a test email from your custom domain address to a personal Gmail account.

  2. Open the email in Gmail, click the three dots in the top-right corner, and select Show original.

  3. Look at the top summary header. You should see an explicit PASS next to all three fields:

  • SPF: PASS with IP...

  • DKIM: PASS with domain yourdomain.com

  • DMARC: PASS

If all three show PASS, your domain is fully authenticated, compliant with modern email security standards, and protected against identity spoofing



Created & Maintained by Pacific Northwest Computers



📞 Pacific Northwest Computers offers Remote & Onsite Support Across: 

SW Washington including Vancouver WA, Battle Ground WA, Camas WA, Washougal WA, Longview WA, Kelso WA, and Portland OR 

No comments:

Post a Comment