XiaTools

Setting Up Google Workspace Email Authentication With Server IPs

Updated 10 Oct 2026

Setting up Google Workspace email authentication requires configuring SPF, DKIM, and understanding how your outbound server IPs interact with Google's mail infrastructure. When you send mail through Google Workspace, Google's mail servers handle the heavy lifting, but third-party applications, on-premises relays, or web servers might also send mail on your behalf, requiring explicit authorization. By correctly publishing SPF and DKIM records, you protect your domain's reputation, prevent spoofing, and ensure your messages bypass spam filters.

To ensure your network configuration is correct from the start, you should first identify your network's public egress points using a reliable utility like the What Is My IP tool on XiaTools, which instantly reveals your current outbound server IP addresses so you can accurately incorporate them into your mail delivery architecture.

Understanding Google Workspace Email Authentication

Email authentication relies on three foundational protocols: SPF (Sender Policy Framework), DKIM (DomainKeys Identified Mail), and DMARC (Domain-based Message Authentication, Reporting, and Conformance). While Google Workspace manages your primary mailbox delivery, your organization often needs to authorize external servers, cloud applications, or dedicated hosting environments to send email using your domain name.

The Role of SPF in Server IP Authorization

SPF is a TXT record published in your DNS that lists all authorized IP addresses and mechanisms permitted to send email on behalf of your domain. Google Workspace provides a standardized SPF include mechanism (_spf.google.com), but if you operate custom backend servers, API nodes, or external relays, you must append their exact IPv4 and IPv6 addresses to your record.

The Role of DKIM in Cryptographic Signing

DKIM adds a cryptographic signature to the header of every outgoing email. Google Workspace generates a public-private key pair; Google's servers sign the outbound mail using the private key, while receiving mail servers query your DNS for the public key to verify the signature. Because DKIM relies on keys rather than IP addresses, it remains secure even if your server IPs change.

Step-by-Step Google Workspace SPF Setup

Configuring your SPF record correctly prevents your legitimate emails from landing in the spam folder. Since Google Workspace enforces strict alignment rules, your SPF record must be concise and free of syntax errors.

1. Identify Your Outbound Server IPs

Before editing your DNS zone, gather all IP addresses that send email for your domain. This includes your local office static IPs, cloud hosting instances (such as AWS, Azure, or DigitalOcean), and transactional email services.

2. Construct the SPF Record Syntax

A standard Google Workspace SPF record combines Google's official include statement with your specific server mechanisms. Avoid exceeding the 10-DNS-lookup limit imposed by the SPF specification.

TXT   @   v=spf1 include:_spf.google.com ip4:192.0.2.1 ip4:192.0.2.25/28 ip6:2001:db8::1 ~all
  • v=spf1: Defines the SPF version.
  • include:_spf.google.com: Authorizes all Google Workspace mail servers.
  • ip4: / ip6:: Explicitly trusts your custom server IPs or CIDR blocks.
  • ~all: Specifies a softfail for unauthorized servers, allowing legitimate migration while flagging suspicious sources.

3. Publish the Record in Your DNS Provider

Log in to your DNS hosting provider, navigate to your domain's DNS manager (menu paths and interface names vary by provider, such as Zone Editor in cPanel or DNS Management in Cloudflare), and create a new TXT record for the root domain (@ or blank) containing your SPF string.

Step-by-Step Google Workspace DKIM Setup

Enabling DKIM inside Google Workspace requires generating a key within the administration console and publishing a matching CNAME record in your DNS zone.

1. Generate DKIM Keys in Google Workspace

  1. Log in to the Google Workspace Admin console using an administrator account.
  2. Navigate to Apps > Google Workspace > Gmail > Authenticate email.
  3. Select your domain from the dropdown menu.
  4. Click Generate new record.
  5. Choose your desired bit length (typically 2048-bit for modern security standards) and note the generated DNS host name (selector) and value (TXT record content).

2. Publish the DKIM Record in DNS

Go to your DNS provider's dashboard and add a new DNS record using the details provided by Google Workspace:

  • Record Type: TXT or CNAME (Google Workspace typically provides a TXT record starting with your selector, such as google._domainkey).
  • Host / Name: google._domainkey
  • Value / Points To: v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQ...

3. Start Authentication in Google Workspace

Return to the Google Workspace Admin console under Authenticate email and click Start authentication. Google will begin verifying the DNS record. Verification can take anywhere from a few minutes up to 48 hours depending on your DNS provider's global propagation speed.

Feature SPF (Sender Policy Framework) DKIM (DomainKeys Identified Mail) DMARC
Primary Function Authorizes sending server IPs Cryptographically signs email headers Policy enforcement and reporting
DNS Record Type TXT TXT TXT (_dmarc.yourdomain.com)
IP Dependency High (Relies on explicit IP/CIDR matching) None (Relies on cryptographic public keys) None
Failure Action Softfail (~all) or Hardfail (-all) Message flagged or rejected Determines action based on policy

Verifying Your Setup With Command-Line Tools

Once your records are published, verify them using command-line diagnostic tools to ensure they resolve correctly across public DNS resolvers.

Checking SPF Records with Dig

Run the following command in your terminal to query your domain's TXT records:

dig TXT example.com +short

Sample expected output:

"v=spf1 include:_spf.google.com ip4:192.0.2.1 ~all"

Checking DKIM Records with Dig

Query your specific DKIM selector to confirm the public key is publicly accessible:

dig TXT google._domainkey.example.com +short

Sample expected output:

"v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQOCAQ8AMIIBCgKCAQEA..."

Testing SMTP Transmission and TLS

You can use openssl to test direct connectivity to Google's inbound mail exchangers or your own outbound relay servers:

openssl s_client -connect smtp.gmail.com:465 -starttls smtp

Common Mistakes and How to Fix Them

  • Multiple SPF Records: Having more than one SPF TXT record breaks validation entirely. Combine all includes and server IPs into a single TXT record.
  • Exceeding the 10-Lookup Limit: Nesting too many include statements causes SPF evaluation to fail. Use IP blocks (ip4: / ip6:) directly instead of nested includes where possible.
  • Typographical Errors in DKIM Selector: Copying the selector or public key with trailing spaces or missing characters results in DKIM signature verification failures at the receiving end.
  • Incorrect Hostname Syntax: Entering google._domainkey.example.com instead of just google._domainkey in DNS panels that automatically append your root domain name.

Configuration Checklist

  • Inventory all third-party servers and static egress server IPs.
  • Draft a single consolidated SPF TXT record containing include:_spf.google.com and your explicit server IPs.
  • Publish the SPF record at the root domain (@).
  • Generate a 2048-bit DKIM key pair inside the Google Workspace Admin console.
  • Add the DKIM TXT record to your DNS provider's zone file.
  • Verify DNS propagation using dig or nslookup commands.
  • Click Start authentication in the Google Workspace dashboard.
  • Send a test email to an external mail tester to verify SPF, DKIM, and DMARC alignment.

Related articles

Free tools