Selector google · SPF include:_spf.google.com — verify yours below, pre-filled for Google Workspace.
Admin console → Apps → Google Workspace → Gmail → Authenticate email. Generate a 2048-bit key, publish the TXT record Google shows at google._domainkey.yourdomain.com, then click "Start authentication".
Google Workspace uses a single selector, google, and a TXT record (not CNAME). New domains sometimes show "authenticating" for up to 48h.
Your SPF TXT record on the root domain must contain include:_spf.google.com. A minimal correct record: v=spf1 include:_spf.google.com ~all. Stacking multiple ESPs? Each include costs DNS lookups against the limit of 10 — count yours here.
DKIM alone doesn't inbox. Run the full domain grade to confirm SPF, DMARC, MX and blacklist status in one shot — Gmail and Microsoft require alignment across all of them for cold outreach in 2026.
Other providers: Microsoft 365 · SendGrid · Mailchimp / Mandrill · Zoho Mail · Any domain