XiaTools

How to Check TXT Record Propagation for Google Workspace Setup

Updated 09 Oct 2026

Verifying your Google Workspace setup requires adding a specific domain verification string to your DNS settings and waiting for global DNS propagation. Because DNS changes take time to replicate across name servers worldwide, performing a timely TXT Lookup lets you instantly query multiple global servers to confirm your ownership record is live.

When setting up Google Workspace, Google gives you a unique verification string that typically starts with google-site-verification=. Until your local and authoritative DNS providers publish this record globally, Google cannot verify your domain, which blocks your email and office app deployment.

Understanding TXT Records and DNS Propagation

A TXT (Text) record is a type of resource record in the Domain Name System used to associate arbitrary text with a host or other name. Originally designed for human-readable notes, TXT records now serve critical machine-readable functions like domain ownership verification, email security frameworks (SPF, DKIM, DMARC), and security policies.

Why TXT Records Take Time to Propagate

DNS is a decentralized, hierarchical database. When you add a TXT record to your authoritative name server (such as Cloudflare, Route 53, or GoDaddy), recursive resolvers across the internet do not immediately see the change. They cache DNS responses based on the Time to Live (TTL) value you configured.

  • Authoritative Server: The primary host where your DNS records live. Updates here happen immediately.
  • Recursive Resolvers: Intermediate servers (like Google Public DNS at 8.8.8.8 or Cloudflare at 1.1.1.1) that query the authoritative server on behalf of users and cache the result.
  • Propagation Delay: The window of time required for TTLs to expire and all recursive resolvers worldwide to fetch the updated TXT record.

How to Add the Google Workspace TXT Record

Before you can check propagation, you must correctly add the record to your DNS host.

  1. Log into your domain registrar or DNS hosting provider.
  2. Navigate to your domain's DNS management or Zone Editor page (menu paths vary by provider, often found under Network Settings, Domain Management, or Advanced DNS).
  3. Create a new DNS record with the following settings:
    • Type: TXT
    • Host / Name: Leave blank, enter @, or put your domain name (e.g., example.com), depending on what your provider requires for root domain records.
    • Value / Text: Paste the exact string provided by Google (e.g., google-site-verification=rX9v7..._sample_string).
    • TTL: Set to a low value like 300 seconds (5 minutes) before making changes, allowing for faster updates.
  4. Save the record.

Methods to Perform a TXT Lookup

You can verify your TXT records using web-based global lookup tools, command-line utilities, or PowerShell scripts. Using multiple methods helps you determine whether propagation issues are global or just localized to your network.

Using Command-Line Tools

1. Using dig (Linux, macOS, and WSL)

The dig utility is the industry standard for querying DNS name servers directly.

dig TXT example.com +noall +answer

Sample output:

example.com.        300     IN      TXT     "google-site-verification=rX9v7_sample_string"

If you want to query a specific public DNS resolver, append the server IP address:

dig @8.8.8.8 TXT example.com +short

2. Using nslookup (Windows Command Prompt)

The nslookup utility works across all major operating systems.

nslookup -type=TXT example.com

Sample output:

Server:  resolver.example.local
Address:  192.0.2.1

example.com     text =
        "google-site-verification=rX9v7_sample_string"

3. Using PowerShell (Windows)

PowerShell offers a native cmdlet to query DNS records directly without external tools.

Resolve-DnsName -Name example.com -Type TXT

Sample output:

Name             Type TTL   Section   Strings
----             ---- ---   -------   -------
example.com      300  Answer    {"google-site-verification=rX9v7_sample_string"}

Comparison of TXT Lookup Methods

Method Speed Global Visibility Ease of Use Best For
Online Tools Instant High (Queries 20+ regions) Very High Quick checks & global validation
dig Command Instant Low (Queries one server) Medium Granular troubleshooting & scripting
nslookup Instant Low (Queries local resolver) Medium Basic checks on Windows endpoints
PowerShell Instant Low (Queries local resolver) High Windows system administration

Common Mistakes and How to Fix Them

Even experienced network administrators occasionally run into issues when adding Google Workspace verification records.

  • Incorrect Host Field: Putting your full domain name in the host field when your provider automatically appends it, resulting in a malformed record like example.com.example.com. Fix: Leave the host field blank or use @ depending on provider rules.
  • Trailing Quotes or Extra Spaces: Copying the Google verification string with accidental whitespace. Fix: Ensure the string matches Google's provided text character-for-character.
  • Conflicting Verification Records: Having multiple conflicting google-site-verification strings from previous attempts. Fix: Delete old, unused Google verification strings unless you are deliberately running multiple services.
  • Ignoring TTL Caching: Expecting instant updates while your local recursive DNS caches the old (non-existent) record. Fix: Use dig @8.8.8.8 to bypass your local ISP cache and query a public resolver directly.

Quick TXT Propagation Checklist

  • Obtained the correct google-site-verification string from Google Workspace admin console.
  • Logged into your authoritative DNS provider.
  • Added a new TXT record with the root domain as the host.
  • Pasted the verification string accurately into the value field.
  • Set a low TTL (e.g., 300 seconds) prior to updating.
  • Waited at least 15 to 30 minutes for initial propagation.
  • Ran a global lookup or executed dig @8.8.8.8 to confirm public visibility.

Frequently asked questions

How long does TXT record propagation take for Google Workspace?

Propagation typically takes anywhere from 5 minutes to 24 hours. The exact duration depends heavily on the TTL value you configured on your DNS host and how quickly global recursive resolvers clear their caches.

Why does Google Workspace fail to verify my domain even though I added the TXT record?

Verification usually fails because the record has not fully propagated globally, or there is a typo in the host name or verification string. Double-check your syntax and query a public DNS resolver like Google's 8.8.8.8 to see if the record is publicly visible.

Can I delete the TXT verification record after Google Workspace is set up?

No. Google periodically re-verifies domain ownership to ensure your settings remain intact. If you delete the TXT record, your workspace services may eventually become suspended or unverified.

What should I enter in the 'Name' or 'Host' field for my root domain?

Most DNS providers require either an '@' symbol, your bare domain name (e.g., example.com), or simply leaving the field completely blank to indicate the root zone. Check your specific DNS provider's documentation for their exact formatting rules.

Can I have multiple TXT records on the same domain?

Yes. Domains frequently host multiple TXT records simultaneously for different services, such as Google verification, SPF email authentication, and DMARC reporting. Each record simply sits alongside the others in your DNS zone.

Related articles

Free tools