Google Workspace DKIM Setup (2026)
google workspace dkim setup is one CNAME or TXT at google._domainkey. Most failures are DNS at the wrong host or authentication started before TTL clears.

What Google Workspace DKIM Actually Does
DKIM adds a cryptographic signature to each message. Receivers fetch the public key from DNS using the selector in the signature. For Workspace the default selector is google, so the host is google._domainkey.yourdomain.com.
Not the same as SPF
SPF authorizes sending IPs. DKIM signs the message body and selected headers. DMARC cares whether the signing domain aligns with the visible From: address. You need all three for Gmail and Microsoft bulk sender expectations in 2026.
Pair this with SPF: zerohook.org/blog/google-workspace-spf-record.
Enable DKIM in Google Admin (Generate the Record)
Sign in as super admin. Open Admin console → Apps → Google Workspace → Gmail → Authenticate email (some consoles label it DKIM authentication).
Select your domain. Click Generate new record. Choose 2048-bit key length when offered. Google shows a hostname and TXT value (some flows use CNAME to Google's hosting; copy exactly what Admin displays).
Typical hostname to publish at your DNS provider:
google._domainkey
Record type and value: paste the full string from Admin into a TXT (or CNAME if Admin says so) on that host. In Cloudflare: DNS → Add record → Type TXT → Name google._domainkey → paste value → Save. TTL Auto is fine.
Wait for propagation. One hour is common; high TTL zones can take longer. In Admin click Start authentication only after a public lookup returns the new value.
Send a test to a personal Gmail. Open the message → Show original. Find Authentication-Results for google.com. You want dkim=pass with d=yourdomain.com.
Mistakes That Keep dkim=fail
Wrong DNS zone
You bought the domain at GoDaddy but nameservers point to Cloudflare. The TXT belongs in Cloudflare, not the registrar parking page.
Typo in the host name
google._domainkey is one label under the apex. Publishing on @ or duplicating the domain in the name field creates a record at the wrong FQDN.
Two DKIM keys fighting
Regenerating in Admin without removing the old TXT leaves two public keys. Delete the previous google._domainkey value before you publish a replacement.
ESP mail still unsigned
Workspace DKIM covers mail sent through Gmail. Mailchimp or HubSpot need their own DKIM CNAMEs. Headers on marketing mail won't show Google's selector.
Pro tip
Frequently Asked Questions
Key takeaways
Generate the key in Admin, publish google._domainkey at your live DNS host, then Start authentication.
Prefer 2048-bit keys when Admin offers the choice.
Verify with Gmail Show original before you declare DMARC ready.
ESP and Workspace DKIM are separate jobs on the same brand domain.
dkim=pass with dmarc=fail means alignment or policy, not a missing TXT.
Share this analysis
Help others discover this content