Google Cloud DNS: Step-by-Step DKIM Record Deployment
Configuring DKIM (DomainKeys Identified Mail) in Google Cloud Platform (GCP) involves publishing a specially formatted TXT record to your Cloud DNS managed zone to digitally sign your outbound emails. Correctly executing a GCP Cloud DNS DKIM setup ensures receiving mail servers can verify your identity, drastically reducing the likelihood of your legitimate messages landing in the spam folder. Whether you are migrating domains or hardening email security, getting the record syntax and selector right on the first try is essential.
Understanding DKIM and GCP Cloud DNS Basics
DKIM adds an encrypted cryptographic signature to the headers of every outgoing email. When a receiving server gets an email claiming to be from example.com, it queries the Domain Name System (DNS) for the public key matching the selector provided in the email header. If the public key successfully decrypts the signature, the message passes authentication.
GCP Cloud DNS serves as Google's authoritative DNS hosting service, offering high reliability and low latency through Anycast DNS servers. Managing your DNS records here requires navigating the Google Cloud Console, locating your managed zone, and creating a new record set using the public key provided by your email service provider (such as Google Workspace, Microsoft 365, or a third-party marketing platform).
Before publishing your records, it is a good idea to validate what your current configuration looks like. You can use the DKIM Checker to quickly inspect existing selector records and verify that your public keys are accessible across global DNS resolvers.
Step 1: Obtain Your DKIM Record from Your Email Provider
Before you touch GCP Cloud DNS, you must generate your DKIM keys within your email provider's admin console.
- Log in to your email provider's administrative dashboard (e.g., Google Workspace Admin Console or Microsoft 365 Defender).
- Navigate to the email authentication or security settings section.
- Select your domain (
example.com) and click Generate New Record. - Note down the two critical pieces of information provided:
- Selector: A unique string (e.g.,
google,smtp, ors1024) used to identify the public key. - Value / TXT Record Content: A long string starting with
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BA....
- Selector: A unique string (e.g.,
Keep this information open in a separate window, as you will need to copy and paste these exact strings into the Google Cloud Console.
Step 2: Add the DKIM Record in GCP Cloud DNS
With your selector and public key ready, you can now configure the zone in the Google Cloud Console. Depending on your organization's workflow, you might use the web interface or the gcloud command-line utility.
Using the Google Cloud Console
- Open the Google Cloud Console and navigate to your project.
- In the navigation menu, select Networking > Cloud DNS.
- Click on the name of the managed zone corresponding to your domain (e.g.,
example-com-zone). - Click Add Record Set at the top of the DNS zone details page.
- Configure the record fields using the values from your email provider:
- DNS Name: Enter your selector followed by
._domainkey. For example, if your selector isgoogle, entergoogle._domainkey. (Note: GCP Cloud DNS will automatically append your zone name, so do not typegoogle._domainkey.example.com.). - Resource Record Type: Select TXT from the dropdown menu.
- TTL (Time to Live): Leave the default (e.g.,
5 minutesor1 hour) or set it to3600seconds during testing. - TXT Data: Paste the entire public key string provided by your email host. If the string is very long or wrapped in quotes by your provider, ensure you paste it cleanly without hard line breaks.
- DNS Name: Enter your selector followed by
- Click Create to save the record.
Using the Google Cloud SDK (gcloud CLI)
If you prefer automation or terminal-based management, you can add the record set using the gcloud dns record-sets transaction commands:
# Start a transaction on your managed zone
gcloud dns record-sets transaction start --zone="example-com-zone"
# Add the DKIM TXT record
gcloud dns record-sets transaction add \
"v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA..." \
--name="google._domainkey.example.com." \
--ttl=3600 \
--type="TXT" \
--zone="example-com-zone"
# Execute the transaction
gcloud dns record-sets transaction execute --zone="example-com-zone"
Step 3: Verify Your GCP Cloud DNS DKIM Setup
DNS propagation usually takes only a few seconds in Cloud DNS, but global propagation can occasionally take up to a few minutes. You should verify that your public key is publicly resolvable before enabling DKIM signing in your email host.
Querying via dig
Run the following command in your terminal to query your public DNS record:
dig TXT google._domainkey.example.com +short
Expected output sample:
"v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA0z3..."
Querying via nslookup on Windows PowerShell
If you are using Windows, you can use PowerShell to perform the lookup:
Resolve-DnsName -Name "google._domainkey.example.com" -Type TXT
If the command returns your exact DKIM public key string, your GCP Cloud DNS DKIM setup is publicly accessible and correctly published.
| Record Component | Description | Example Value |
|---|---|---|
| Name / Host | Selector plus ._domainkey |
google._domainkey |
| Type | DNS record type | TXT |
| TTL | Caching duration in seconds | 3600 |
| Value / Data | Public cryptographic key payload | v=DKIM1; k=rsa; p=... |
Step 4: Enable DKIM Signing in Your Email Host
Publishing the DNS record alone does not turn on signing; it only provides the public key so receivers can verify messages.
- Return to your email provider's admin console (Google Workspace, Microsoft 365, etc.).
- Locate the DKIM management section where you generated the key.
- Click Start Authentication or Enable DKIM.
- Send a test email to an external inbox (such as a personal Gmail or Outlook account) and inspect the email headers to confirm that
Authentication-Resultsshowsdkim=pass. Note that menu paths may differ slightly depending on your specific version or provider updates.
Common Mistakes and Troubleshooting
Even experienced engineers occasionally run into subtle configuration issues when deploying DNS records in cloud environments.
- Trailing Domain Name Duplication: A frequent mistake in GCP Cloud DNS is entering
google._domainkey.example.com.into the DNS Name field instead of justgoogle._domainkey. Cloud DNS automatically appends the apex domain, resulting in an erroneous lookup forgoogle._domainkey.example.com.example.com. Always check your final fully qualified domain name (FQDN). - Unescaped Quotes or Line Breaks: Long RSA keys often wrap across multiple lines when copied from email provider dashboards. Ensure you paste the key as a single continuous string without internal line breaks or accidental newline characters.
- Incorrect Selector Mismatch: If your email provider generates a selector named
s2048, but you publish the record under the selectorgoogle, verification will fail. The selector in the DNS record must match the selector announced in the email header signature. - Propagation Delay Confusion: If your initial lookup fails immediately after creation, verify your zone file syntax and wait 5 minutes before troubleshooting further.
DKIM Deployment Checklist
- Generated DKIM key and recorded the selector string.
- Created a new TXT record in GCP Cloud DNS with the format
selector._domainkey. - Pasted the complete public key string into the TXT Data field without extra line breaks.
- Verified record visibility using
digornslookupcommands. - Enabled DKIM signing inside the email provider's admin console.
- Sent a test email and confirmed
dkim=passin the internet headers.