DMARC for Google Workspace
dmarc google workspace setup lives in DNS at _dmarc, not in Admin. Workspace signs mail; your policy tells Gmail what to do when alignment fails.

_dmarc TXT you publish at DNS, not in Admin, and p=none still lets spoofed mail through while legitimate Workspace DKIM passes.Prerequisites on Workspace (Do These First)
Google does not create your DMARC record when you verify the domain. Admin covers SPF guidance and DKIM keys; receivers read your policy from _dmarc.yourdomain.com after they judge alignment on mail that left Gmail.
SPF on the apex
Publish v=spf1 include:_spf.google.com -all if Workspace is your only sender. Template: zerohook.org/blog/google-workspace-spf-record.
DKIM signing on
Generate the key in Admin → Gmail → Authenticate email, publish google._domainkey, click Start authentication. Walkthrough: zerohook.org/blog/google-workspace-dkim-setup.
Alignment test
Send from Gmail as [email protected] to a personal Gmail. Show original should show dkim=pass with d=yourdomain.com and ideally spf=pass on the aligned domain. If either leg fails, fix that before you publish DMARC with quarantine or reject.
Starter DMARC Record (Monitor Phase)
Publish one TXT at host _dmarc on the root domain:
v=DMARC1; p=none; rua=mailto:[email protected]; adkim=r; aspf=r; pct=100Tag cheat sheet
p=none monitors failures without telling receivers to block. rua= sends aggregate XML to the address you control (use a mailbox or a report parser). Relaxed alignment (adkim=r, aspf=r) is the usual SMB default so subdomains and common ESP setups do not break on day one.
Policy stages (none vs quarantine vs reject): zerohook.org/blog/dmarc-policy-explained-none-quarantine-reject. This post stays on Workspace plumbing, not a second copy of that pillar.
Publish at Your DNS Host
Cloudflare: DNS → Add record → Type TXT → Name _dmarc → paste the single DMARC line → Save.
GoDaddy / Route 53 / Namecheap: same idea. Host is _dmarc, not @. Value is one string starting with v=DMARC1.
Confirm propagation:
dig +short TXT _dmarc.yourdomain.comSend another Gmail test. Authentication-Results should include dmarc=pass for legitimate Workspace mail once the record is visible.
After two to four weeks of clean RUA reports (no surprise failing sources), plan quarantine with pct= staging. Eight-week path: zerohook.org/blog/dmarc-p-reject-rollout-8-weeks.
Workspace-specific gotchas
Marketing mail from Mailchimp or HubSpot does not inherit Workspace DKIM. Each ESP needs its own keys and SPF includes, or DMARC fails on those streams while Gmail mail passes.
Google Groups and some aliases can change From: or signing context. Test the addresses you actually use in production, not only your primary user mailbox.
Third-party SMTP relays that send as your domain without DKIM alignment will show up in aggregate reports under p=none. Fix or authorize them before you raise policy.
Warning
p=reject while an old payroll system still sends without alignment will bounce payroll. None first, inventory from RUA, then enforce.Frequently Asked Questions
Key takeaways
Publish DMARC at _dmarc after Workspace SPF and DKIM pass alignment tests.
Start with p=none and rua= to inventory senders before quarantine or reject.
ESP and Workspace authentication are separate; RUA exposes gaps early.
Use the policy pillar for none vs quarantine vs reject semantics, not a duplicate article.
Validate with Gmail Show original and zerohook.org/dmarc-checker after every DNS edit.
Share this analysis
Help others discover this content
More from our blog

Gmail Unverified Sender? Check DMARC
Gmail shows an unverified sender warning when DMARC, SPF, or DKIM alignment fails on your From domain. Fix steps for M365, Google Workspace, Mailchimp, and HubSpot relay mail.

DMARC Alignment Failed, SPF Passed
When DMARC alignment fails but SPF passes, your envelope-from or DKIM domain does not match the visible sender. Quick diagnosis from Authentication-Results and ESP fix steps.

DMARC Policy: None vs Quarantine vs Reject
Choosing a DMARC policy is not a one-time DNS edit. None monitors, quarantine filters, reject blocks unauthenticated mail. Rollout order, pct= staging, and provider-specific pitfalls for 2026.