How to Set Up DMARC for Google Workspace

Email authentication operations

Publish the record only after you know who is allowed to send as the domain.

DMARC tells receiving mail systems how to handle messages that fail aligned SPF or DKIM checks and where to send reports. Google recommends setting up SPF and DKIM first, monitoring before enforcement, and increasing quarantine or reject coverage gradually.

Plan DNS and email changesReview CMS Max email delivery
  • SPF and DKIM first
  • Monitor with p=none
  • Review alignment reports
  • Stage enforcement
DMARC setup for Google Workspace email
DMARC protects a domain best when every legitimate sender is inventoried, authenticated, aligned, monitored, and assigned an owner.

Decision frame

Do not start with a copied reject record.

A strict policy can block legitimate mail if marketing, support, billing, forms, commerce, CRM, newsletters, or other services are not aligned. Begin with a sender inventory and valid SPF and DKIM, then use aggregate reports to find gaps before enforcement.
01

Authenticate first

Publish one valid SPF policy for the domain and enable DKIM signing for Google Workspace and each supported sender where applicable.

02

Monitor before enforcing

Start with p=none and a controlled aggregate-report mailbox so the team can identify legitimate and unauthorized sources.

03

Increase policy gradually

Move a small percentage to quarantine, monitor results, correct failures, then expand quarantine or reject based on accepted risk.

Practical controls

DMARC is a cross-system inventory and monitoring program.

DNS is the publication layer; the real work is knowing every sender and maintaining alignment as systems change.
01 / Control

Sender inventory

List Google Workspace, website forms, CMS notifications, commerce, CRM, help desk, billing, newsletters, signatures, devices, and vendors.

02 / Control

SPF design

Keep a single SPF record within provider and DNS lookup constraints and include only approved sending infrastructure.

03 / Control

DKIM signing

Enable supported domain signing for Google Workspace and approved services, protect selectors and keys, and plan rotation.

04 / Control

DMARC alignment

Understand whether the visible From domain aligns with the domain validated by SPF or DKIM under the chosen alignment mode.

05 / Control

Report handling

Route aggregate reports to a controlled mailbox or service, parse the data, protect access, and create an exception workflow.

06 / Control

Change management

Review authentication whenever a sender, DNS provider, email platform, domain, subdomain, or routing path changes.

Implementation workflow

Move from inventory to enforcement without surprising the business.

The timeline depends on sending complexity and report evidence, not a universal number of days.
  1. 01

    Inventory

    Identify every legitimate service that sends mail using the domain in the visible From address.

  2. 02

    Authenticate

    Configure and validate SPF and DKIM for Google Workspace and each accepted sender.

  3. 03

    Publish

    Create the _dmarc TXT record with p=none and a secured aggregate-report destination.

  4. 04

    Analyze

    Review reports over representative business cycles, correct alignment failures, and investigate unknown sources.

  5. 05

    Enforce

    Introduce quarantine for a limited percentage, monitor, expand deliberately, and move to reject only when accepted.

Practical reference

Understand the fields before editing DNS.

Use the current Google guidance and the organization's accepted policy rather than pasting a generic record blindly.
v=DMARC1
Declares the DMARC protocol version and appears first in the record.
p=none
Requests monitoring with no DMARC enforcement action from the domain owner.
p=quarantine
Requests that failing messages receive suspicious treatment such as spam placement.
p=reject
Requests rejection of messages that fail the accepted DMARC evaluation.
rua=mailto:
Specifies an aggregate-report address that the organization controls and is prepared to process.

Current evidence

Verify the live standard, provider, and platform guidance.

Products, policies, interfaces, standards, and search systems change. Use current primary documentation and test the production implementation before release.
Google Workspace AdminSet up DMARCGoogle Workspace AdminRecommended DMARC rolloutGoogle Workspace AdminSet up DKIMCMS MaxSMTP integration

Frequently asked questions

Resolve the common assumptions before launch.

Each answer identifies a decision, responsibility, test, or operating boundary that the team should document.
What is a safe first DMARC policy?

After SPF and DKIM are configured, Google recommends beginning with p=none for monitoring and then increasing enforcement gradually.

Should the host be _dmarc.domain.com?

The record is published at _dmarc for the policy domain. DNS interfaces differ: some expect only _dmarc and append the zone automatically. Verify the final fully qualified name.

Can DMARC block legitimate mail?

Yes. A quarantine or reject policy can affect legitimate but misaligned senders, which is why the sender inventory and monitoring stage matter.

Does CMS website email need to be reviewed?

Yes. Forms, orders, account notices, marketing tools, CRM, help desk, and any vendor using the visible From domain belong in the sender inventory.

Make DNS and email authentication changes with a complete sender inventory.

CMS Max can help identify website and commerce senders, coordinate DNS ownership, validate delivery workflows, and document the handoff to the organization's email administrator.

Talk with CMS MaxReview CMS Max email delivery

Building Relationships with Web Developers and Marketing Agencies that want better results

The world's fastest and most SEO friendly website code.