Google Workspace: DKIM Selector & SPF Setup

Selector google · SPF include:_spf.google.com — verify yours below, pre-filled for Google Workspace.

Google Workspace DKIM setup

Admin console → Apps → Google Workspace → Gmail → Authenticate email. Generate a 2048-bit key, publish the TXT record Google shows at google._domainkey.yourdomain.com, then click "Start authentication".

Google Workspace uses a single selector, google, and a TXT record (not CNAME). New domains sometimes show "authenticating" for up to 48h.

Google Workspace SPF record

Your SPF TXT record on the root domain must contain include:_spf.google.com. A minimal correct record: v=spf1 include:_spf.google.com ~all. Stacking multiple ESPs? Each include costs DNS lookups against the limit of 10 — count yours here.

Verify all three pillars

DKIM alone doesn't inbox. Run the full domain grade to confirm SPF, DMARC, MX and blacklist status in one shot — Gmail and Microsoft require alignment across all of them for cold outreach in 2026.

Google Workspace rotates keys. Records drift. Interns edit DNS.

Aurelius re-verifies your DKIM, SPF, DMARC and blacklist status continuously and emails you on any regression. Free for 2 domains.

Start monitoring free