XiaTools

Google Workspace Domain Verification and Registration Records

Updated 11 Oct 2026

Verifying your custom domain with Google Workspace requires adding specific DNS records—usually a TXT record or a CNAME record—to prove ownership to Google's servers. Without this crucial verification step, you cannot activate Gmail, create user accounts, or use other core productivity apps tied to your brand. Before you start updating your DNS zones, it is always a good practice to check your domain's registration status and history using the Domain Age Checker on XiaTools to ensure your nameservers are active and properly propagating.

Understanding Google Workspace Domain Verification Records

When you sign up for Google Workspace, Google needs to confirm that you actually own and control the domain name you entered. To do this, Google generates a unique verification string. You must take this string and publish it in your public DNS zone file as either a TXT record or, in some cases, a CNAME record.

Google checks your domain's DNS database for this exact string. Once Google's automated scanners locate the record, ownership is verified, and you can proceed to configure your Mail Exchange (MX) records, Sender Policy Framework (SPF), DomainKeys Identified Mail (DKIM), and Domain-based Message Authentication, Reporting, and Conformance (DMARC) records.

Types of Verification Records

Google primarily relies on two types of DNS records for domain ownership verification:

  1. TXT Record (Recommended): This is the most common and flexible method. It adds a text string to your root domain without affecting web traffic or existing email routing.
  2. CNAME Record (Alternative): Used if you cannot edit TXT records at your registrar. It points a unique auto-generated subdomain to a Google-owned verification target.

Step-by-Step Guide to Adding Verification Records

Follow this structured workflow to generate, publish, and test your Google Workspace verification records.

Step 1: Obtain the Record from the Google Admin Console

Log in to your Google Workspace Admin Console using your super administrator account. If you are in the middle of a new setup wizard, the domain verification screen will automatically appear. If you are adding a secondary domain later, navigate to Account > Domains > Manage domains, click Add a domain, and select the verification method.

Google will display a string that looks similar to this example value:

google-site-verification=rX9K3mP8vL2nQ5wZ1sF7jH4tD6bC0yX3mA9pE5qW2r

Step 2: Log In to Your DNS Provider

Open a new browser tab and log in to the domain registrar or DNS hosting provider where your domain's nameservers are hosted (such as Cloudflare, GoDaddy, Namecheap, or AWS Route 53).

Note: Provider menu paths vary, but you will generally look for sections labeled DNS Management, DNS Zone Editor, or Manage Nameservers. Ensure your domain is using the DNS provider you think it is. If you recently transferred your domain, verify its status and authoritative nameservers using tools like the XiaTools Domain Age Checker.

Step 3: Create the DNS Record

Add a new record to your root domain zone with the following exact parameters depending on the record type:

  • Record Type: TXT
  • Host / Name: @ (or leave blank for the root domain, depending on your provider)
  • Value / Text: google-site-verification=rX9K3mP8vL2nQ5wZ1sF7jH4tD6bC0yX3mA9pE5qW2r
  • TTL (Time to Live): 3600 seconds (or default)

If you are using the CNAME method instead, the structure will look like this:

  • Record Type: CNAME
  • Host / Name: google1234567890abcdef (the unique hash provided by Google)
  • Points to / Target: ghs.googlehosted.com
  • TTL: 3600

Step 4: Save and Verify in Google Admin

Save your changes in your DNS management panel. Return to the Google Admin Console and click the Verify or Protect button.

Because of DNS propagation delays, Google might not see the record immediately. If you receive an error stating the record was not found, wait between 15 and 60 minutes and try clicking verify again.

Command-Line Verification Techniques

Before clicking verify in the browser, network engineers often check DNS propagation directly via the command line. You can use standard network utilities to confirm your records are live.

Using dig on Linux and macOS

Open your terminal and run the dig command to query the TXT records for your domain (example.com):

dig TXT example.com +short

If your record has successfully propagated, you will see output that includes your Google verification string:

"v=spf1 include:_spf.google.com ~all"
"google-site-verification=rX9K3mP8vL2nQ5wZ1sF7jH4tD6bC0yX3mA9pE5qW2r"

Using PowerShell on Windows

If you are running Windows, use the built-in Resolve-DnsName cmdlet in PowerShell:

Resolve-DnsName -Name example.com -Type TXT

Look through the output to ensure the Strings property displays your Google verification token clearly.

Comparing Domain Verification Methods

Method Pros Cons Best Used For
TXT Record Does not interfere with web traffic; industry standard. Can be accidentally overwritten if zone files are mismanaged. Primary domains and root domain setups.
CNAME Record Easy to spot in zone files; strict target mapping. Cannot be used on root domains at certain legacy DNS providers. Subdomains or when TXT editing is locked.
HTML File Upload Quick if you already have web hosting active. Fails if your web server goes down or redirects improperly. Advanced webmasters with active web servers.

Common Mistakes and How to Fix Them

Even experienced administrators occasionally run into issues when setting up workspace records. Avoid these common pitfalls:

  • Formatting Errors: Forgetting the google-site-verification= prefix or introducing trailing spaces in the text field will cause validation to fail instantly. Copy and paste the entire string directly from Google.
  • Incorrect Host Field: Entering example.com. instead of @ in the host field can result in the record being appended incorrectly as example.com.example.com. Check your provider's documentation on whether root records require an empty field, @, or the full domain name.
  • Not Waiting for Propagation: DNS changes take time. If you added the record two minutes ago, Google's automated tool may time out. Give it up to an hour for global nameservers to update.
  • Conflicting Records: If you previously registered the domain with Google Workspace under a different account, old verification records might still exist in your zone file. Remove obsolete google-site-verification entries before adding new ones.

Quick Setup Checklist

  • Logged into the Google Workspace Admin Console and copied the verification string.
  • Checked domain registration and nameservers using the XiaTools Domain Age Checker.
  • Created a TXT record at your DNS host with @ as the name.
  • Pasted the exact google-site-verification=... string as the value.
  • Tested propagation using dig or Resolve-DnsName.
  • Clicked Verify in the Google Admin Console.

Frequently asked questions

What should I do if Google Workspace says my verification record was not found?

First, double-check that you copied the verification string without any typos or trailing spaces. Next, use a command-line tool like dig or PowerShell to confirm the record is publicly visible. If it appears in your local queries, wait up to 24 hours for full global DNS propagation before trying again.

Can I delete the Google verification TXT record after my account is set up?

No, you must keep the verification TXT record in your DNS zone for the lifetime of your Google Workspace subscription. Google periodically re-verifies domain ownership in the background. If the record is removed, your account services may eventually be suspended.

What is the difference between verifying a root domain and a subdomain?

Verifying a root domain like example.com covers all users and subdomains under it. Verifying a subdomain like mail.example.com only gives you administrative control over that specific branch and requires placing the record under the subdomain host instead of the root.

Why does my DNS provider reject the @ symbol in the host field?

Some legacy DNS panels do not recognize the @ symbol as shorthand for the root domain. In these rare cases, you can usually leave the host or name field completely blank, or enter your full domain name ending with a dot, depending on your registrar's specific interface rules.

Can I have multiple google-site-verification records on the same domain?

Yes. If multiple Google services or distinct Google Workspace organizations need to verify administrative rights over the same domain, you can safely add multiple distinct TXT records without causing conflicts.

Related articles

Free tools