XiaTools

Google Cloud DNS: Step-by-Step DKIM Record Deployment

Updated 11 Oct 2026

Configuring DKIM (DomainKeys Identified Mail) in Google Cloud Platform (GCP) involves publishing a specially formatted TXT record to your Cloud DNS managed zone to digitally sign your outbound emails. Correctly executing a GCP Cloud DNS DKIM setup ensures receiving mail servers can verify your identity, drastically reducing the likelihood of your legitimate messages landing in the spam folder. Whether you are migrating domains or hardening email security, getting the record syntax and selector right on the first try is essential.

Understanding DKIM and GCP Cloud DNS Basics

DKIM adds an encrypted cryptographic signature to the headers of every outgoing email. When a receiving server gets an email claiming to be from example.com, it queries the Domain Name System (DNS) for the public key matching the selector provided in the email header. If the public key successfully decrypts the signature, the message passes authentication.

GCP Cloud DNS serves as Google's authoritative DNS hosting service, offering high reliability and low latency through Anycast DNS servers. Managing your DNS records here requires navigating the Google Cloud Console, locating your managed zone, and creating a new record set using the public key provided by your email service provider (such as Google Workspace, Microsoft 365, or a third-party marketing platform).

Before publishing your records, it is a good idea to validate what your current configuration looks like. You can use the DKIM Checker to quickly inspect existing selector records and verify that your public keys are accessible across global DNS resolvers.

Step 1: Obtain Your DKIM Record from Your Email Provider

Before you touch GCP Cloud DNS, you must generate your DKIM keys within your email provider's admin console.

  1. Log in to your email provider's administrative dashboard (e.g., Google Workspace Admin Console or Microsoft 365 Defender).
  2. Navigate to the email authentication or security settings section.
  3. Select your domain (example.com) and click Generate New Record.
  4. Note down the two critical pieces of information provided:
    • Selector: A unique string (e.g., google, smtp, or s1024) used to identify the public key.
    • Value / TXT Record Content: A long string starting with v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BA....

Keep this information open in a separate window, as you will need to copy and paste these exact strings into the Google Cloud Console.

Step 2: Add the DKIM Record in GCP Cloud DNS

With your selector and public key ready, you can now configure the zone in the Google Cloud Console. Depending on your organization's workflow, you might use the web interface or the gcloud command-line utility.

Using the Google Cloud Console

  1. Open the Google Cloud Console and navigate to your project.
  2. In the navigation menu, select Networking > Cloud DNS.
  3. Click on the name of the managed zone corresponding to your domain (e.g., example-com-zone).
  4. Click Add Record Set at the top of the DNS zone details page.
  5. Configure the record fields using the values from your email provider:
    • DNS Name: Enter your selector followed by ._domainkey. For example, if your selector is google, enter google._domainkey. (Note: GCP Cloud DNS will automatically append your zone name, so do not type google._domainkey.example.com.).
    • Resource Record Type: Select TXT from the dropdown menu.
    • TTL (Time to Live): Leave the default (e.g., 5 minutes or 1 hour) or set it to 3600 seconds during testing.
    • TXT Data: Paste the entire public key string provided by your email host. If the string is very long or wrapped in quotes by your provider, ensure you paste it cleanly without hard line breaks.
  6. Click Create to save the record.

Using the Google Cloud SDK (gcloud CLI)

If you prefer automation or terminal-based management, you can add the record set using the gcloud dns record-sets transaction commands:

# Start a transaction on your managed zone
gcloud dns record-sets transaction start --zone="example-com-zone"

# Add the DKIM TXT record
gcloud dns record-sets transaction add \
    "v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA..." \
    --name="google._domainkey.example.com." \
    --ttl=3600 \
    --type="TXT" \
    --zone="example-com-zone"

# Execute the transaction
gcloud dns record-sets transaction execute --zone="example-com-zone"

Step 3: Verify Your GCP Cloud DNS DKIM Setup

DNS propagation usually takes only a few seconds in Cloud DNS, but global propagation can occasionally take up to a few minutes. You should verify that your public key is publicly resolvable before enabling DKIM signing in your email host.

Querying via dig

Run the following command in your terminal to query your public DNS record:

dig TXT google._domainkey.example.com +short

Expected output sample:

"v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA0z3..."

Querying via nslookup on Windows PowerShell

If you are using Windows, you can use PowerShell to perform the lookup:

Resolve-DnsName -Name "google._domainkey.example.com" -Type TXT

If the command returns your exact DKIM public key string, your GCP Cloud DNS DKIM setup is publicly accessible and correctly published.

Record Component Description Example Value
Name / Host Selector plus ._domainkey google._domainkey
Type DNS record type TXT
TTL Caching duration in seconds 3600
Value / Data Public cryptographic key payload v=DKIM1; k=rsa; p=...

Step 4: Enable DKIM Signing in Your Email Host

Publishing the DNS record alone does not turn on signing; it only provides the public key so receivers can verify messages.

  1. Return to your email provider's admin console (Google Workspace, Microsoft 365, etc.).
  2. Locate the DKIM management section where you generated the key.
  3. Click Start Authentication or Enable DKIM.
  4. Send a test email to an external inbox (such as a personal Gmail or Outlook account) and inspect the email headers to confirm that Authentication-Results shows dkim=pass. Note that menu paths may differ slightly depending on your specific version or provider updates.

Common Mistakes and Troubleshooting

Even experienced engineers occasionally run into subtle configuration issues when deploying DNS records in cloud environments.

  • Trailing Domain Name Duplication: A frequent mistake in GCP Cloud DNS is entering google._domainkey.example.com. into the DNS Name field instead of just google._domainkey. Cloud DNS automatically appends the apex domain, resulting in an erroneous lookup for google._domainkey.example.com.example.com. Always check your final fully qualified domain name (FQDN).
  • Unescaped Quotes or Line Breaks: Long RSA keys often wrap across multiple lines when copied from email provider dashboards. Ensure you paste the key as a single continuous string without internal line breaks or accidental newline characters.
  • Incorrect Selector Mismatch: If your email provider generates a selector named s2048, but you publish the record under the selector google, verification will fail. The selector in the DNS record must match the selector announced in the email header signature.
  • Propagation Delay Confusion: If your initial lookup fails immediately after creation, verify your zone file syntax and wait 5 minutes before troubleshooting further.

DKIM Deployment Checklist

  • Generated DKIM key and recorded the selector string.
  • Created a new TXT record in GCP Cloud DNS with the format selector._domainkey.
  • Pasted the complete public key string into the TXT Data field without extra line breaks.
  • Verified record visibility using dig or nslookup commands.
  • Enabled DKIM signing inside the email provider's admin console.
  • Sent a test email and confirmed dkim=pass in the internet headers.

Frequently asked questions

What is the correct DNS record name format for GCP Cloud DNS DKIM setup?

You must format the DNS Name field as your provider-specified selector followed by `._domainkey` (for example, `google._domainkey`). Because GCP Cloud DNS automatically appends your apex domain name to the record, do not type your full domain name in this field.

How long does it take for GCP Cloud DNS DKIM records to propagate?

Cloud DNS updates globally within seconds due to Google's infrastructure. However, downstream caching by receiving mail servers or local machine resolvers might take up to a few minutes or match the TTL value you defined.

Can I use the same DKIM record for multiple email providers?

No. Each email provider requires its own unique selector and public key pair. If you send mail through both Google Workspace and an external marketing platform, you must publish a separate DKIM TXT record for each respective selector.

Why does my email header show dkim=fail after adding the DNS record?

This usually happens if you forgot to activate DKIM signing in your email provider's admin console after publishing the DNS record, or if there is a typo in your public key string such as an accidental line break.

Do I need to update my SPF record when setting up DKIM?

While SPF and DKIM are separate email authentication protocols, best practices dictate that you implement SPF, DKIM, and DMARC together. Setting up DKIM does not automatically modify your SPF record, but you should ensure your SPF record authorizes your email senders as well.

Related articles

Free tools