100% Client-Side EngineZero data storage • No email signup required • 2026 Google & Yahoo Bulk Sender Compliant
Business Email Suite 2026 Google & Yahoo Compliant

Google Workspace (Gmail) SPF & DMARC Setup Guide

Google Workspace requires domain owners to publish _spf.google.com to authorize Google mail transfer agents. Under 2026 bulk sender regulations, Google strictly enforces SPF alignment and a published DMARC policy for all outgoing business mail.

Business Email SuiteRFC 7208 & RFC 7489 Validated

Google Workspace (Gmail) DNS Preset Generator

Enter your domain below to customize the exact SPF and DMARC TXT records required for Google Workspace (Gmail).

RFC 7208 DNS Lookup Cost4 of 10 Lookups

1 primary include query + 3 recursive netblock lookups (4 lookups total). Google Workspace consumes 4 of your 10 allowable RFC 7208 lookups due to internal netblock pointers. If you combine it with SendGrid, HubSpot, or other tools, track your lookup count carefully to prevent PermError.

Lookup Budget4/10
Exclusive Partner PromoSetting up Google Workspace for your domain?

Get 10% off your first year on Business Starter (Promo: VCKVUL4TL9KDXXL) or Business Standard (Promo: 7D3CAELD9Q7AJGM).

Get 10% Off Google Workspace
RECORD 1: SPFHost: @ (or apex domain)Type: TXT
v=spf1 include:_spf.google.com ~all

⚠️ Important: If your domain already publishes an existing SPF record, merge include:_spf.google.com into that record. Never publish two separate SPF records.

RECORD 2: DMARCHost: _dmarc (or _dmarc.example.com)Type: TXT
v=DMARC1; p=quarantine; rua=mailto:dmarc-reports@example.com; pct=100; adkim=r; aspf=r

This policy enforces p=quarantine (suspicious emails routed to spam) and directs daily XML compliance reports to dmarc-reports@example.com.

Live DNS Propagation Check for example.com

Query Cloudflare DNS-over-HTTPS in real-time to check if your domain already publishes valid records.

Using Google Workspace (Gmail) alongside other platforms?Open Multi-Provider SPF Merger & Lookup Calculator
Step-by-Step Instructions

How to configure Google Workspace (Gmail) in your DNS

Follow these 4 straightforward steps to publish your authentication records on Cloudflare, GoDaddy, Namecheap, or AWS Route 53.

1

Check for Existing SPF Records

Never publish two SPF records for the same domain. If your DNS already contains a v=spf1 record, edit the existing TXT record instead of creating a second one.

2

Add Google Workspace Include

Add include:_spf.google.com to your SPF TXT record at the root domain (@). Finish the record with ~all (SoftFail).

v=spf1 include:_spf.google.com ~all
3

Generate and Publish DMARC Policy

Create a new DNS TXT record with Host _dmarc. Start with p=none for 7 days to collect diagnostic reports, then upgrade to p=quarantine.

v=DMARC1; p=quarantine; rua=mailto:dmarc-reports@yourdomain.com; pct=100
4

Verify DNS Propagation

Use our Live DNS Inspector tool below to confirm Google Workspace SPF and DMARC have propagated across global DNS resolvers.

Technical Q&A

Frequently Asked Questions for Google Workspace (Gmail)

Technical answers regarding lookup limits, multiple records, and delivery errors.

Why does Google Workspace consume 4 SPF lookups?▼
_spf.google.com references three nested TXT records (_netblocks.google.com, _netblocks2.google.com, and _netblocks3.google.com) to cover all Google Cloud IP ranges. Each nested reference costs 1 DNS lookup, totaling 4 RFC 7208 queries.
Can I have multiple SPF records if I use Google Workspace and SendGrid?▼
No. RFC 7208 Section 3.2 explicitly dictates that a domain MUST NOT publish more than one SPF record. You must merge them into a single record: v=spf1 include:_spf.google.com include:sendgrid.net ~all.
What happens if Google bulk sender rules are not met in 2026?▼
Emails sent from domains without valid SPF, DKIM, and DMARC records will encounter temporary rejection (4xx SMTP errors) or permanent delivery failure (5xx SMTP codes) when delivering to Gmail recipients.
How do I configure DKIM for Google Workspace?▼
In the Google Admin Console, go to Apps > Google Workspace > Gmail > Authenticate email. Generate a 2048-bit DKIM key, copy the TXT record (Host: google._domainkey), and publish it to your DNS registrar.

Common Providers Used with Google Workspace (Gmail)

Send marketing and transactional emails alongside your corporate inbox.

View All 50+ Guides
Full Email Deliverability Suite

Need to combine multiple providers into one SPF record?

Our full in-browser engine merges SPF records, calculates RFC 7208 lookups in real-time, and generates custom DMARC policies.