How to Check TXT Record Propagation for Google Workspace Setup
Verifying your Google Workspace setup requires adding a specific domain verification string to your DNS settings and waiting for global DNS propagation. Because DNS changes take time to replicate across name servers worldwide, performing a timely TXT Lookup lets you instantly query multiple global servers to confirm your ownership record is live.
When setting up Google Workspace, Google gives you a unique verification string that typically starts with google-site-verification=. Until your local and authoritative DNS providers publish this record globally, Google cannot verify your domain, which blocks your email and office app deployment.
Understanding TXT Records and DNS Propagation
A TXT (Text) record is a type of resource record in the Domain Name System used to associate arbitrary text with a host or other name. Originally designed for human-readable notes, TXT records now serve critical machine-readable functions like domain ownership verification, email security frameworks (SPF, DKIM, DMARC), and security policies.
Why TXT Records Take Time to Propagate
DNS is a decentralized, hierarchical database. When you add a TXT record to your authoritative name server (such as Cloudflare, Route 53, or GoDaddy), recursive resolvers across the internet do not immediately see the change. They cache DNS responses based on the Time to Live (TTL) value you configured.
- Authoritative Server: The primary host where your DNS records live. Updates here happen immediately.
- Recursive Resolvers: Intermediate servers (like Google Public DNS at
8.8.8.8or Cloudflare at1.1.1.1) that query the authoritative server on behalf of users and cache the result. - Propagation Delay: The window of time required for TTLs to expire and all recursive resolvers worldwide to fetch the updated TXT record.
How to Add the Google Workspace TXT Record
Before you can check propagation, you must correctly add the record to your DNS host.
- Log into your domain registrar or DNS hosting provider.
- Navigate to your domain's DNS management or Zone Editor page (menu paths vary by provider, often found under Network Settings, Domain Management, or Advanced DNS).
- Create a new DNS record with the following settings:
- Type:
TXT - Host / Name: Leave blank, enter
@, or put your domain name (e.g.,example.com), depending on what your provider requires for root domain records. - Value / Text: Paste the exact string provided by Google (e.g.,
google-site-verification=rX9v7..._sample_string). - TTL: Set to a low value like
300seconds (5 minutes) before making changes, allowing for faster updates.
- Type:
- Save the record.
Methods to Perform a TXT Lookup
You can verify your TXT records using web-based global lookup tools, command-line utilities, or PowerShell scripts. Using multiple methods helps you determine whether propagation issues are global or just localized to your network.
Using Command-Line Tools
1. Using dig (Linux, macOS, and WSL)
The dig utility is the industry standard for querying DNS name servers directly.
dig TXT example.com +noall +answer
Sample output:
example.com. 300 IN TXT "google-site-verification=rX9v7_sample_string"
If you want to query a specific public DNS resolver, append the server IP address:
dig @8.8.8.8 TXT example.com +short
2. Using nslookup (Windows Command Prompt)
The nslookup utility works across all major operating systems.
nslookup -type=TXT example.com
Sample output:
Server: resolver.example.local
Address: 192.0.2.1
example.com text =
"google-site-verification=rX9v7_sample_string"
3. Using PowerShell (Windows)
PowerShell offers a native cmdlet to query DNS records directly without external tools.
Resolve-DnsName -Name example.com -Type TXT
Sample output:
Name Type TTL Section Strings
---- ---- --- ------- -------
example.com 300 Answer {"google-site-verification=rX9v7_sample_string"}
Comparison of TXT Lookup Methods
| Method | Speed | Global Visibility | Ease of Use | Best For |
|---|---|---|---|---|
| Online Tools | Instant | High (Queries 20+ regions) | Very High | Quick checks & global validation |
dig Command |
Instant | Low (Queries one server) | Medium | Granular troubleshooting & scripting |
nslookup |
Instant | Low (Queries local resolver) | Medium | Basic checks on Windows endpoints |
| PowerShell | Instant | Low (Queries local resolver) | High | Windows system administration |
Common Mistakes and How to Fix Them
Even experienced network administrators occasionally run into issues when adding Google Workspace verification records.
- Incorrect Host Field: Putting your full domain name in the host field when your provider automatically appends it, resulting in a malformed record like
example.com.example.com. Fix: Leave the host field blank or use@depending on provider rules. - Trailing Quotes or Extra Spaces: Copying the Google verification string with accidental whitespace. Fix: Ensure the string matches Google's provided text character-for-character.
- Conflicting Verification Records: Having multiple conflicting
google-site-verificationstrings from previous attempts. Fix: Delete old, unused Google verification strings unless you are deliberately running multiple services. - Ignoring TTL Caching: Expecting instant updates while your local recursive DNS caches the old (non-existent) record. Fix: Use
dig @8.8.8.8to bypass your local ISP cache and query a public resolver directly.
Quick TXT Propagation Checklist
- Obtained the correct
google-site-verificationstring from Google Workspace admin console. - Logged into your authoritative DNS provider.
- Added a new
TXTrecord with the root domain as the host. - Pasted the verification string accurately into the value field.
- Set a low TTL (e.g., 300 seconds) prior to updating.
- Waited at least 15 to 30 minutes for initial propagation.
- Ran a global lookup or executed
dig @8.8.8.8to confirm public visibility.