Google Workspace DKIM Activation and Verification Guide
Setting up DomainKeys Identified Mail (DKIM) for Google Workspace ensures that your outbound emails are cryptographically signed, significantly reducing the chances of your messages landing in the spam folder. Without proper DKIM configuration, receiving mail servers cannot verify that an email truly originated from your domain, leaving your brand vulnerable to spoofing. This step-by-step guide walks you through generating your custom keys in the Google Admin console, publishing the correct DNS records, and activating authentication for your domain.
Understanding How Google Workspace DKIM Works
When you configure DKIM, your Google Workspace environment attaches a digital signature to the header of every outgoing email. The receiving mail server uses the public key published in your domain's DNS records to verify this signature. If the signature matches, the email passes authentication checks, building trust with inbox providers like Gmail, Outlook, and Yahoo.
Historically, email spoofing was trivial because the Simple Mail Transfer Protocol (SMTP) does not inherently verify the sender address in the From: header. DKIM, combined with SPF and DMARC, closes this security gap. Google Workspace allows you to use its default google selector, but setting up a custom selector using your own domain name provides superior branding and administrative control.
Step 1: Generate Your DKIM Record in Google Admin
Before touching your DNS provider, you must generate the cryptographic key pair within your Google Workspace administration console.
- Log in to the Google Admin console using an administrator account.
- Navigate through the menu to Apps > Google Workspace > Gmail > Authenticate email.
- If you manage multiple domains, select the specific domain you want to configure from the dropdown menu.
- Click the Generate new record button.
- In the configuration window, choose your preferred bit length. While 1024-bit is supported, 2048-bit is strongly recommended for modern cryptographic security unless your DNS host has strict character limits.
- Leave the selector prefix as the default (usually
google) or enter a custom prefix of your choice. - Click Generate. Google will display your new DNS host name (selector) and the TXT record value.
Keep this browser tab open, as you will need to copy and paste these exact strings into your DNS management portal.
Step 2: Publish the DNS TXT Record
Next, you need to publish the public key in your domain's DNS zone file. Log into your domain registrar or DNS hosting provider (such as Cloudflare, GoDaddy, or AWS Route 53). Note that exact menu paths and interface labels vary by provider, but the core DNS record parameters remain identical.
Create a new TXT record using the following parameters supplied by Google Workspace:
- Record Type:
TXT - Host Name / Name / Alias:
[selector]._domainkey(For example, if your selector isgoogle, entergoogle._domainkeyorgoogle._domainkey.example.comdepending on your host's interface requirements). - Value / Text / Points To:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA...(Paste the complete long string provided by Google). - TTL (Time to Live): Set to 3600 seconds (1 hour) or the default.
| DNS Field | Example Value | Description |
|---|---|---|
| Type | TXT | Specifies the record type for text data |
| Host | google._domainkey |
Combines your selector with the mandatory _domainkey label |
| Value | v=DKIM1; k=rsa; p=... |
The public cryptographic key generated by Google |
| TTL | 3600 | Caching duration on global nameservers |
Save the record and allow time for global DNS propagation, which typically takes anywhere from a few minutes up to 24 hours depending on your TTL settings and registrar.
Step 3: Start Authentication in Google Workspace
Once your DNS record has had time to propagate across the internet, return to the Google Admin console to activate the signature process.
- Return to Apps > Google Workspace > Gmail > Authenticate email.
- Locate the domain you configured.
- Click the Start authentication button.
When you click this button, Google attempts to query your public DNS to verify that the TXT record exists and matches the private key stored on Google's outbound mail servers. If the verification succeeds, the status indicator will change to green, and Google will immediately begin cryptographically signing all outbound emails sent from your domain.
Step 4: Verify Your Configuration
Never assume your setup is correct without testing it. You can check your work using the free DKIM Checker on XiaTools to instantly validate your DNS record syntax, selector placement, and public key validity before sending live traffic.
Additionally, you can use command-line utilities to query your DNS records directly. Open your terminal or PowerShell and run a dig query:
dig TXT google._domainkey.example.com +short
Sample Output:
"v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA0z3..."
To perform a real-world test, send an email from your Google Workspace account to an external testing address (such as mail-tester.com or your personal Gmail account). Open the raw message source (in Gmail, click the three vertical dots and select Show original) and look for the authentication summary headers:
Authentication-Results: mx.google.com;
dkim=pass header.i=@example.com header.s=google header.b=AbC123Xy
Common Mistakes and Troubleshooting
Even experienced engineers occasionally run into hurdles during email authentication rollouts. Review these frequent pitfalls to keep your deployment smooth:
- DNS Hostname Formatting Error: Many DNS providers automatically append your root domain name to the host field. If you enter
google._domainkey.example.cominto a provider that auto-appends, your record becomesgoogle._domainkey.example.com.example.com, causing lookups to fail. Always check your provider's documentation on whether to input fully qualified domain names or relative labels. - Exceeding Character Limits in 2048-bit Keys: Older DNS management panels struggle with strings longer than 255 characters. If your registrar splits TXT strings automatically, ensure it formats them correctly without breaking the cryptographic key inside the
p=tag. - Premature Activation: Clicking Start authentication before DNS records have fully propagated results in an error. If Google fails to find the record, wait 30 minutes for propagation and try again.
- Forgetting DMARC Alignment: DKIM is a critical pillar for DMARC. Ensure your
From:header domain matches the domain specified in thed=tag of your DKIM signature to achieve proper DMARC alignment.
DKIM Setup Checklist
- Generate 2048-bit DKIM keys inside the Google Admin console.
- Create the TXT record with the correct
[selector]._domainkeyhost naming. - Verify record syntax and public key integrity using XiaTools.
- Click Start authentication in Google Workspace.
- Send a test email and inspect the message header for
dkim=pass.