ZeroHook
ProductSolutionsBlogToolsPricingCompanyContact sales
Run a free scan
  • Product
  • Solutions
  • Blog
  • Tools
  • Pricing
  • Company
  • Contact sales
Sign inRun a free scan
ZeroHook

DNS and email security auditing, without the enterprise contract.

ZeroHook on Product Hunt — Let's stop spoofed email and ship audit proof today.Review ZeroHook on Product Hunt

Explore

  • Product
  • Solutions
  • Blog
  • Tools
  • Pricing

Resources

  • Help center

Company

  • About
  • Contact
  • Contact sales

Legal

  • Privacy
  • Terms
  • Cookies
  • Legal notice

New DNS advisories, monthly

What broke, who it hit, and the record that fixes it.

© 2026 ZeroHook. All rights reserved.

Back to blog
DMARC

DMARC for Google Workspace

dmarc google workspace setup lives in DNS at _dmarc, not in Admin. Workspace signs mail; your policy tells Gmail what to do when alignment fails.

ZeroHook
ZeroHook Team
Security Analysts
Oct 4, 2026~3 min read
DMARC for Google Workspace
dmarc google workspace setup is the _dmarc TXT you publish at DNS, not in Admin, and p=none still lets spoofed mail through while legitimate Workspace DKIM passes.

Prerequisites on Workspace (Do These First)

Google does not create your DMARC record when you verify the domain. Admin covers SPF guidance and DKIM keys; receivers read your policy from _dmarc.yourdomain.com after they judge alignment on mail that left Gmail.

SPF on the apex

Publish v=spf1 include:_spf.google.com -all if Workspace is your only sender. Template: zerohook.org/blog/google-workspace-spf-record.

DKIM signing on

Generate the key in Admin → Gmail → Authenticate email, publish google._domainkey, click Start authentication. Walkthrough: zerohook.org/blog/google-workspace-dkim-setup.

Alignment test

Send from Gmail as [email protected] to a personal Gmail. Show original should show dkim=pass with d=yourdomain.com and ideally spf=pass on the aligned domain. If either leg fails, fix that before you publish DMARC with quarantine or reject.

Starter DMARC Record (Monitor Phase)

Publish one TXT at host _dmarc on the root domain:

v=DMARC1; p=none; rua=mailto:[email protected]; adkim=r; aspf=r; pct=100

Tag cheat sheet

p=none monitors failures without telling receivers to block. rua= sends aggregate XML to the address you control (use a mailbox or a report parser). Relaxed alignment (adkim=r, aspf=r) is the usual SMB default so subdomains and common ESP setups do not break on day one.

Policy stages (none vs quarantine vs reject): zerohook.org/blog/dmarc-policy-explained-none-quarantine-reject. This post stays on Workspace plumbing, not a second copy of that pillar.

Publish at Your DNS Host

1

Cloudflare: DNS → Add record → Type TXT → Name _dmarc → paste the single DMARC line → Save.

2

GoDaddy / Route 53 / Namecheap: same idea. Host is _dmarc, not @. Value is one string starting with v=DMARC1.

3

Confirm propagation:

dig +short TXT _dmarc.yourdomain.com
4

Send another Gmail test. Authentication-Results should include dmarc=pass for legitimate Workspace mail once the record is visible.

5

After two to four weeks of clean RUA reports (no surprise failing sources), plan quarantine with pct= staging. Eight-week path: zerohook.org/blog/dmarc-p-reject-rollout-8-weeks.

Workspace-specific gotchas

Marketing mail from Mailchimp or HubSpot does not inherit Workspace DKIM. Each ESP needs its own keys and SPF includes, or DMARC fails on those streams while Gmail mail passes.

Google Groups and some aliases can change From: or signing context. Test the addresses you actually use in production, not only your primary user mailbox.

Third-party SMTP relays that send as your domain without DKIM alignment will show up in aggregate reports under p=none. Fix or authorize them before you raise policy.

Warning

Jumping straight to p=reject while an old payroll system still sends without alignment will bounce payroll. None first, inventory from RUA, then enforce.

Frequently Asked Questions

Key takeaways

1

Publish DMARC at _dmarc after Workspace SPF and DKIM pass alignment tests.

2

Start with p=none and rua= to inventory senders before quarantine or reject.

3

ESP and Workspace authentication are separate; RUA exposes gaps early.

4

Use the policy pillar for none vs quarantine vs reject semantics, not a duplicate article.

5

Validate with Gmail Show original and zerohook.org/dmarc-checker after every DNS edit.

Check DMARC, SPF, and DKIM in one pass at zerohook.org/dmarc-checker once _dmarc is live, before you move policy off none.

Share this analysis

Help others discover this content

Fix DNS before the next audit
Provider-specific copy-paste fixes for Cloudflare, Route53, GoDaddy, and more.
Start free scan

More from our blog

Gmail Unverified Sender? Check DMARC
DMARC

Gmail Unverified Sender? Check DMARC

Gmail shows an unverified sender warning when DMARC, SPF, or DKIM alignment fails on your From domain. Fix steps for M365, Google Workspace, Mailchimp, and HubSpot relay mail.

DMARC Alignment Failed, SPF Passed
DMARC

DMARC Alignment Failed, SPF Passed

When DMARC alignment fails but SPF passes, your envelope-from or DKIM domain does not match the visible sender. Quick diagnosis from Authentication-Results and ESP fix steps.

DMARC Policy: None vs Quarantine vs Reject
DMARC

DMARC Policy: None vs Quarantine vs Reject

Choosing a DMARC policy is not a one-time DNS edit. None monitors, quarantine filters, reject blocks unauthenticated mail. Rollout order, pct= staging, and provider-specific pitfalls for 2026.