Authenticate first
Publish one valid SPF policy for the domain and enable DKIM signing for Google Workspace and each supported sender where applicable.
Email authentication operations
Publish the record only after you know who is allowed to send as the domain.
DMARC tells receiving mail systems how to handle messages that fail aligned SPF or DKIM checks and where to send reports. Google recommends setting up SPF and DKIM first, monitoring before enforcement, and increasing quarantine or reject coverage gradually.

Decision frame
Publish one valid SPF policy for the domain and enable DKIM signing for Google Workspace and each supported sender where applicable.
Start with p=none and a controlled aggregate-report mailbox so the team can identify legitimate and unauthorized sources.
Move a small percentage to quarantine, monitor results, correct failures, then expand quarantine or reject based on accepted risk.
Practical controls
List Google Workspace, website forms, CMS notifications, commerce, CRM, help desk, billing, newsletters, signatures, devices, and vendors.
Keep a single SPF record within provider and DNS lookup constraints and include only approved sending infrastructure.
Enable supported domain signing for Google Workspace and approved services, protect selectors and keys, and plan rotation.
Understand whether the visible From domain aligns with the domain validated by SPF or DKIM under the chosen alignment mode.
Route aggregate reports to a controlled mailbox or service, parse the data, protect access, and create an exception workflow.
Review authentication whenever a sender, DNS provider, email platform, domain, subdomain, or routing path changes.
Implementation workflow
Identify every legitimate service that sends mail using the domain in the visible From address.
Configure and validate SPF and DKIM for Google Workspace and each accepted sender.
Create the _dmarc TXT record with p=none and a secured aggregate-report destination.
Review reports over representative business cycles, correct alignment failures, and investigate unknown sources.
Introduce quarantine for a limited percentage, monitor, expand deliberately, and move to reject only when accepted.
Practical reference
Current evidence
Frequently asked questions
After SPF and DKIM are configured, Google recommends beginning with p=none for monitoring and then increasing enforcement gradually.
The record is published at _dmarc for the policy domain. DNS interfaces differ: some expect only _dmarc and append the zone automatically. Verify the final fully qualified name.
Yes. A quarantine or reject policy can affect legitimate but misaligned senders, which is why the sender inventory and monitoring stage matter.
Yes. Forms, orders, account notices, marketing tools, CRM, help desk, and any vendor using the visible From domain belong in the sender inventory.
CMS Max can help identify website and commerce senders, coordinate DNS ownership, validate delivery workflows, and document the handoff to the organization's email administrator.
The world's fastest and most SEO friendly website code.