XiaTools

Google Workspace DKIM Activation and Verification Guide

Updated 10 Oct 2026

Setting up DomainKeys Identified Mail (DKIM) for Google Workspace ensures that your outbound emails are cryptographically signed, significantly reducing the chances of your messages landing in the spam folder. Without proper DKIM configuration, receiving mail servers cannot verify that an email truly originated from your domain, leaving your brand vulnerable to spoofing. This step-by-step guide walks you through generating your custom keys in the Google Admin console, publishing the correct DNS records, and activating authentication for your domain.

Understanding How Google Workspace DKIM Works

When you configure DKIM, your Google Workspace environment attaches a digital signature to the header of every outgoing email. The receiving mail server uses the public key published in your domain's DNS records to verify this signature. If the signature matches, the email passes authentication checks, building trust with inbox providers like Gmail, Outlook, and Yahoo.

Historically, email spoofing was trivial because the Simple Mail Transfer Protocol (SMTP) does not inherently verify the sender address in the From: header. DKIM, combined with SPF and DMARC, closes this security gap. Google Workspace allows you to use its default google selector, but setting up a custom selector using your own domain name provides superior branding and administrative control.

Step 1: Generate Your DKIM Record in Google Admin

Before touching your DNS provider, you must generate the cryptographic key pair within your Google Workspace administration console.

  1. Log in to the Google Admin console using an administrator account.
  2. Navigate through the menu to Apps > Google Workspace > Gmail > Authenticate email.
  3. If you manage multiple domains, select the specific domain you want to configure from the dropdown menu.
  4. Click the Generate new record button.
  5. In the configuration window, choose your preferred bit length. While 1024-bit is supported, 2048-bit is strongly recommended for modern cryptographic security unless your DNS host has strict character limits.
  6. Leave the selector prefix as the default (usually google) or enter a custom prefix of your choice.
  7. Click Generate. Google will display your new DNS host name (selector) and the TXT record value.

Keep this browser tab open, as you will need to copy and paste these exact strings into your DNS management portal.

Step 2: Publish the DNS TXT Record

Next, you need to publish the public key in your domain's DNS zone file. Log into your domain registrar or DNS hosting provider (such as Cloudflare, GoDaddy, or AWS Route 53). Note that exact menu paths and interface labels vary by provider, but the core DNS record parameters remain identical.

Create a new TXT record using the following parameters supplied by Google Workspace:

  • Record Type: TXT
  • Host Name / Name / Alias: [selector]._domainkey (For example, if your selector is google, enter google._domainkey or google._domainkey.example.com depending on your host's interface requirements).
  • Value / Text / Points To: v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA... (Paste the complete long string provided by Google).
  • TTL (Time to Live): Set to 3600 seconds (1 hour) or the default.
DNS Field Example Value Description
Type TXT Specifies the record type for text data
Host google._domainkey Combines your selector with the mandatory _domainkey label
Value v=DKIM1; k=rsa; p=... The public cryptographic key generated by Google
TTL 3600 Caching duration on global nameservers

Save the record and allow time for global DNS propagation, which typically takes anywhere from a few minutes up to 24 hours depending on your TTL settings and registrar.

Step 3: Start Authentication in Google Workspace

Once your DNS record has had time to propagate across the internet, return to the Google Admin console to activate the signature process.

  1. Return to Apps > Google Workspace > Gmail > Authenticate email.
  2. Locate the domain you configured.
  3. Click the Start authentication button.

When you click this button, Google attempts to query your public DNS to verify that the TXT record exists and matches the private key stored on Google's outbound mail servers. If the verification succeeds, the status indicator will change to green, and Google will immediately begin cryptographically signing all outbound emails sent from your domain.

Step 4: Verify Your Configuration

Never assume your setup is correct without testing it. You can check your work using the free DKIM Checker on XiaTools to instantly validate your DNS record syntax, selector placement, and public key validity before sending live traffic.

Additionally, you can use command-line utilities to query your DNS records directly. Open your terminal or PowerShell and run a dig query:

dig TXT google._domainkey.example.com +short

Sample Output:

"v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA0z3..."

To perform a real-world test, send an email from your Google Workspace account to an external testing address (such as mail-tester.com or your personal Gmail account). Open the raw message source (in Gmail, click the three vertical dots and select Show original) and look for the authentication summary headers:

Authentication-Results: mx.google.com;
       dkim=pass header.i=@example.com header.s=google header.b=AbC123Xy

Common Mistakes and Troubleshooting

Even experienced engineers occasionally run into hurdles during email authentication rollouts. Review these frequent pitfalls to keep your deployment smooth:

  • DNS Hostname Formatting Error: Many DNS providers automatically append your root domain name to the host field. If you enter google._domainkey.example.com into a provider that auto-appends, your record becomes google._domainkey.example.com.example.com, causing lookups to fail. Always check your provider's documentation on whether to input fully qualified domain names or relative labels.
  • Exceeding Character Limits in 2048-bit Keys: Older DNS management panels struggle with strings longer than 255 characters. If your registrar splits TXT strings automatically, ensure it formats them correctly without breaking the cryptographic key inside the p= tag.
  • Premature Activation: Clicking Start authentication before DNS records have fully propagated results in an error. If Google fails to find the record, wait 30 minutes for propagation and try again.
  • Forgetting DMARC Alignment: DKIM is a critical pillar for DMARC. Ensure your From: header domain matches the domain specified in the d= tag of your DKIM signature to achieve proper DMARC alignment.

DKIM Setup Checklist

  • Generate 2048-bit DKIM keys inside the Google Admin console.
  • Create the TXT record with the correct [selector]._domainkey host naming.
  • Verify record syntax and public key integrity using XiaTools.
  • Click Start authentication in Google Workspace.
  • Send a test email and inspect the message header for dkim=pass.

Frequently asked questions

How long does DNS propagation take for a new Google Workspace DKIM record?

DNS propagation typically takes anywhere from 5 minutes to 24 hours, depending on your DNS hosting provider and the Time to Live (TTL) values you configured. Most modern DNS providers update globally within 15 to 30 minutes.

Should I choose a 1024-bit or 2048-bit key length for my domain?

You should always choose a 2048-bit key length unless your DNS provider explicitly lacks support for longer TXT strings. 2048-bit keys offer significantly stronger security against modern cryptographic attacks.

What happens to my email if I change my DNS records without disabling authentication first?

If you modify or delete your active DKIM DNS records without updating Google Workspace first, receiving servers will fail to verify your outgoing mail signatures. This can cause legitimate emails to be marked as spam or rejected entirely until the records are corrected.

Can I use the same DKIM selector across multiple domains in Google Workspace?

No, each domain managed within your Google Workspace tenant requires its own unique DKIM record and selector combination generated specifically for that domain name.

Why does Google Workspace show a verification error even though I added the TXT record?

Verification errors usually stem from a formatting typo in the host name or record value, or from incomplete DNS propagation. Double-check that your host field does not have duplicated domain names due to auto-appending by your registrar.

Related articles

Free tools