7 min read Diesen Artikel auf Deutsch lesen

Google Workspace DNS Records: MX, SPF, DKIM

The short answer

Google Workspace needs five kinds of DNS record: a verification TXT, an MX record (smtp.google.com, priority 1), one SPF TXT record that includes _spf.google.com, a DKIM TXT at google._domainkey that you generate in the Admin console, and a DMARC TXT at _dmarc. If you also send through Brevo, as EmailFlow OS does, add Brevo's own DKIM records and keep SPF as one combined record.

In this article

Which Google Workspace DNS records does a domain actually need?

A Google Workspace domain needs a small, fixed set of records. Each one does its own job, and mixing them up causes most setup failures. Verification proves to Google that you own the domain. MX tells other servers where to deliver mail for you. SPF, DKIM and DMARC are about the mail you send. Nothing in this table is optional if you plan to send cold email from the domain. Gmail's bulk sender rules, which kick in at 5,000 messages a day to Gmail addresses, require SPF, DKIM and a DMARC record of at least p=none, and Google expects authentication from smaller senders too.

Record Type Host / name Value (example)
Domain verification TXT @ google-site-verification=… (string from the Admin console)
Inbound mail MX @ smtp.google.com, priority 1
SPF TXT @ v=spf1 include:_spf.google.com ~all
DKIM TXT google._domainkey v=DKIM1; k=rsa; p=… (generated in the Admin console)
DMARC TXT _dmarc v=DMARC1; p=none; rua=mailto:dmarc@yourdomain.com
Core Google Workspace DNS records. The verification and DKIM values are unique to your tenant, so copy them from the Admin console.

Google says DNS changes can take up to 48 hours to show up everywhere, though most resolve within your record's TTL.

What are the Google Workspace DNS records for email sending?

The records for sending email are SPF, DKIM and DMARC. MX only covers receiving. SPF (RFC 7208) lists the servers allowed to send for your domain. DKIM (RFC 6376) adds a cryptographic signature that receivers check against a public key in DNS. DMARC (RFC 7489) tells receivers what to do when a message's From domain doesn't line up with a passing SPF or DKIM result. Set them up in this order:

  1. SPF: publish exactly one TXT record at the root that starts with v=spf1 and includes _spf.google.com. If you publish two SPF records, the result is a permerror and SPF fails.
  2. DKIM: in the Admin console, go to Apps > Google Workspace > Gmail > Authenticate email, generate a 2048-bit key and publish it as TXT at google._domainkey.
  3. DKIM activation: once the record resolves, go back to the same screen and click Start authentication. Until you do, Gmail won't sign with your key.
  4. DMARC: publish v=DMARC1; p=none with a rua address so you get aggregate reports before you tighten the policy.
  5. Stay under SPF's limit of 10 DNS lookups. Every include counts, and so do any nested includes inside it.

A 2048-bit DKIM key is longer than the 255-character limit for a single TXT string. Some DNS hosts split it for you and some don't. G Suite DKIM for Google Workspace and Brevo covers the splitting in detail.

What are the Google Workspace DNS MX records?

Google Workspace domains set up from 2023 onward use a single MX record: smtp.google.com with priority 1. Older domains often still have the legacy set of five records, and Google still supports them. You can keep either set, but don't mix them, and don't leave records that point at your old host. When several MX records are present, sending servers try the lowest priority number first. A leftover MX pointing at a previous provider therefore splits your inbound mail between two systems.

Setup MX host Priority
Current (single record) smtp.google.com 1
Legacy ASPMX.L.GOOGLE.COM 1
Legacy ALT1.ASPMX.L.GOOGLE.COM 5
Legacy ALT2.ASPMX.L.GOOGLE.COM 5
Legacy ALT3.ASPMX.L.GOOGLE.COM 10
Legacy ALT4.ASPMX.L.GOOGLE.COM 10
Google Workspace MX values. Use either the single record or the full legacy set, never both.

MX doesn't affect outbound authentication, but it does matter for cold outreach. Replies to your messages go to the address in From or Reply-To, and if MX is wrong, those replies bounce or end up somewhere you never check. Run dig MX yourdomain.com and confirm that only Google hosts come back.

How do you add Google Workspace DNS records in GoDaddy?

In GoDaddy, you add Google Workspace records under My Products > Domains > DNS. For some registrars, including GoDaddy, the Admin console offers to set up verification and MX automatically. That's fine, but check the result. If you add records by hand, follow these steps:

  1. Check the nameservers first. If they point to another DNS host, records you edit in GoDaddy have no effect. Make the changes wherever the nameservers point.
  2. Delete GoDaddy's default MX records, which usually point at secureserver.net, before you add smtp.google.com with priority 1.
  3. Put @ in the Host field for the root. GoDaddy appends the domain itself, so typing google._domainkey.yourdomain.com produces google._domainkey.yourdomain.com.yourdomain.com.
  4. Edit the existing SPF TXT record if there is one, rather than adding a second record that starts with v=spf1.
  5. Paste the DKIM value in full. If GoDaddy rejects it or shortens it, check it with dig TXT google._domainkey.yourdomain.com before you click Start authentication.

GoDaddy's doubled-hostname problem also hits Brevo's DKIM records, and GoDaddy DKIM setup for Brevo senders shows how to check the selector.

Do Google Workspace DNS records cover mail sent through Brevo?

No. Google's google._domainkey key only signs mail that leaves Google's servers. EmailFlow OS works like this: you record one video and upload it, connect your own Brevo account and sending domain, and import your prospect list into EmailFlow OS. EmailFlow OS then makes a personalised version of that recording for each recipient and sends it through your Brevo account, from your domain. Brevo is the sending server, not Google. So the domain needs Brevo's DKIM records, exactly as Brevo shows them in its domain authentication settings, alongside Google's. The two coexist because each uses a different selector.

SPF is where people slip up. Combine everything into one record, not one per provider. Each include costs lookups toward the limit of 10. DMARC alignment passes when either SPF or DKIM aligns with the From domain, so a Brevo DKIM key published on your own domain is what lets the Brevo-sent mail align. Because the domain and the Brevo account are yours, the records stay in your DNS and under your control. DKIM DMARC and SPF for cold email senders explains how alignment works.

Why do Google Workspace DNS records fail even when they look right?

Most failures come down to a handful of causes you can find with dig, or with Show Original in Gmail, which prints the SPF, DKIM and DMARC results for a received message:

  • Two SPF records at the root: SPF returns permerror, and receivers treat it as a fail.
  • More than 10 DNS lookups in SPF: same permerror, often caused by stacking one include per tool.
  • A DKIM key that was published but never activated: the record exists, but Gmail isn't signing until you click Start authentication.
  • A truncated DKIM key: the DNS host cut the value at 255 characters, so the public key doesn't match.
  • A DMARC record at the wrong host: it has to sit at _dmarc. A record at the root is ignored.
  • A stale TTL: you changed a record but resolvers still serve the old value until the TTL expires.

Correct records are a prerequisite. They don't decide where your mail lands, because the receiving server does that. A brand-new domain still needs a gradual volume ramp. Email warm up daily volumes and DNS setup lays out that schedule.

Questions people ask

What is the MX record for Google Workspace?
For domains set up from 2023 onward, it's a single MX record: smtp.google.com with priority 1. Older domains may use the legacy set of five, with ASPMX.L.GOOGLE.COM at priority 1, two ALT hosts at 5 and two at 10. Google supports both, but use one set only, and remove any MX records that point to your previous provider.
What is the SPF record for Google Workspace?
It's v=spf1 include:_spf.google.com ~all, published as one TXT record at the root of the domain. If you also send through Brevo or another service, add its include to the same record. RFC 7208 allows only one SPF record per domain and a maximum of 10 DNS lookups.
How long do Google Workspace DNS records take to work?
Google says changes can take up to 48 hours to propagate, though most resolve within the record's TTL, which is often 1 hour. DKIM has an extra step: once the google._domainkey record resolves, you have to click Start authentication in the Admin console before Gmail signs your mail.
Do I need DMARC for Google Workspace?
Yes, if you send at volume. Gmail's bulk sender rules require a DMARC record of at least p=none from senders who send 5,000 or more messages a day to Gmail addresses. Publish it as TXT at _dmarc.yourdomain.com with a rua address so you receive aggregate reports.

Share

LinkedIn X

Keep reading

All articles