ZeroHook
ProductSolutionsBlogToolsPricingCompanyContact sales
Run a free scan
  • Product
  • Solutions
  • Blog
  • Tools
  • Pricing
  • Company
  • Contact sales
Sign inRun a free scan
ZeroHook

DNS and email security auditing, without the enterprise contract.

ZeroHook on Product Hunt — Let's stop spoofed email and ship audit proof today.Review ZeroHook on Product Hunt

Explore

  • Product
  • Solutions
  • Blog
  • Tools
  • Pricing

Resources

  • Help center

Company

  • About
  • Contact
  • Contact sales

Legal

  • Privacy
  • Terms
  • Cookies
  • Legal notice

New DNS advisories, monthly

What broke, who it hit, and the record that fixes it.

© 2026 ZeroHook. All rights reserved.

Back to blog
DKIM

Google Workspace DKIM Setup (2026)

google workspace dkim setup is one CNAME or TXT at google._domainkey. Most failures are DNS at the wrong host or authentication started before TTL clears.

ZeroHook
ZeroHook Team
Security Analysts
Oct 4, 2026~3 min read
Google Workspace DKIM Setup (2026)
SPF is green in your DNS panel. Gmail still shows dkim=fail on mail you send from Workspace. That's normal until you finish google workspace dkim setup, and Admin won't flip signing on until the public key in DNS matches what Google generated. We've had teams paste the TXT into the website builder's DNS by mistake, or click Start authentication ten minutes after publish. TTL hadn't moved. The fix is almost always the record location, not a broken Workspace tenant.

What Google Workspace DKIM Actually Does

DKIM adds a cryptographic signature to each message. Receivers fetch the public key from DNS using the selector in the signature. For Workspace the default selector is google, so the host is google._domainkey.yourdomain.com.

Not the same as SPF

SPF authorizes sending IPs. DKIM signs the message body and selected headers. DMARC cares whether the signing domain aligns with the visible From: address. You need all three for Gmail and Microsoft bulk sender expectations in 2026.

Pair this with SPF: zerohook.org/blog/google-workspace-spf-record.

Enable DKIM in Google Admin (Generate the Record)

1

Sign in as super admin. Open Admin console → Apps → Google Workspace → Gmail → Authenticate email (some consoles label it DKIM authentication).

2

Select your domain. Click Generate new record. Choose 2048-bit key length when offered. Google shows a hostname and TXT value (some flows use CNAME to Google's hosting; copy exactly what Admin displays).

3

Typical hostname to publish at your DNS provider:

google._domainkey

4

Record type and value: paste the full string from Admin into a TXT (or CNAME if Admin says so) on that host. In Cloudflare: DNS → Add record → Type TXT → Name google._domainkey → paste value → Save. TTL Auto is fine.

5

Wait for propagation. One hour is common; high TTL zones can take longer. In Admin click Start authentication only after a public lookup returns the new value.

6

Send a test to a personal Gmail. Open the message → Show original. Find Authentication-Results for google.com. You want dkim=pass with d=yourdomain.com.

Mistakes That Keep dkim=fail

Wrong DNS zone

You bought the domain at GoDaddy but nameservers point to Cloudflare. The TXT belongs in Cloudflare, not the registrar parking page.

Typo in the host name

google._domainkey is one label under the apex. Publishing on @ or duplicating the domain in the name field creates a record at the wrong FQDN.

Two DKIM keys fighting

Regenerating in Admin without removing the old TXT leaves two public keys. Delete the previous google._domainkey value before you publish a replacement.

ESP mail still unsigned

Workspace DKIM covers mail sent through Gmail. Mailchimp or HubSpot need their own DKIM CNAMEs. Headers on marketing mail won't show Google's selector.

Pro tip

If Show original says dkim=pass but dmarc=fail, alignment is the problem. Fix From: domain and DMARC policy next, not another SPF include.

Frequently Asked Questions

Key takeaways

1

Generate the key in Admin, publish google._domainkey at your live DNS host, then Start authentication.

2

Prefer 2048-bit keys when Admin offers the choice.

3

Verify with Gmail Show original before you declare DMARC ready.

4

ESP and Workspace DKIM are separate jobs on the same brand domain.

5

dkim=pass with dmarc=fail means alignment or policy, not a missing TXT.

Run SPF, DKIM, and DMARC together at zerohook.org/dns-health-check after you publish google._domainkey so the next migration does not leave headers contradicting your dashboard.

Share this analysis

Help others discover this content

Fix DNS before the next audit
Provider-specific copy-paste fixes for Cloudflare, Route53, GoDaddy, and more.
Start free scan