Skip to content
Warmuply

Google Workspace SPF on GoDaddy, plus DKIM and DMARC

The Warmuply TeamLast checked: October 2026

Your domain is with GoDaddy, your email runs on Google Workspace, and you're getting ready for your first mail merge. This guide shows you exactly how to set up the Google Workspace SPF record on GoDaddy, then DKIM and DMARC, with the values to paste and where each one goes on GoDaddy's DNS page.

It takes about 20 minutes of clicking, then up to 48 hours for everything to take effect. You'll need to sign in to both GoDaddy and the Google Admin console (the settings area for your Workspace account).

What you'll add to GoDaddy

You'll add or edit three TXT records (records that hold a line of text) on your domain's DNS page. DNS is the public address book for your domain, and GoDaddy hosts it if you bought your domain there.

SettingWhat it doesTypeName in GoDaddyValue
SPFLists the servers allowed to send email as youTXT@v=spf1 include:_spf.google.com ~all
DKIMAdds a digital signature to every email you sendTXTgoogle._domainkeyThe key you copy from Google
DMARCTells receivers what to do with email that fails the checksTXT_dmarcv=DMARC1; p=none; rua=mailto:dmarc-reports@yourcompany.com

DNS records for yourcompany.com

  • SPF: who may send

    Type
    TXT
    Name
    @
    Value
    v=spf1 include:_spf.google.com ~all
  • DKIM: your signature (copy from Google)

    Type
    TXT
    Name
    google._domainkey
    Value
    v=DKIM1; k=rsa; p=…
  • DMARC: what to do if checks fail

    Type
    TXT
    Name
    _dmarc
    Value
    v=DMARC1; p=none; rua=mailto:dmarc-reports@yourcompany.com

One of each. Edit, don’t duplicate.

All three are TXT records on the same page. Each one has its own Name.

GoDaddy adds your domain to the Name for you. Type _dmarc, not _dmarc.yourcompany.com.

Before you start: check what's already on GoDaddy

Look before you add anything. Two things on GoDaddy commonly trip people up.

  1. Sign in to your GoDaddy Domain Portfolio and select your domain to open Domain Settings.
  2. Select DNS to see your records.
  3. Look for a TXT record whose value starts with v=spf1. GoDaddy says only one SPF record works on a domain at a time, so if one exists, you'll edit it rather than add a second.
  4. Look for a TXT record with the Name _dmarc. Since April 2025, GoDaddy has added a default DMARC record with a "quarantine" policy to domains bought or transferred into GoDaddy. You'll edit this one too.

Records you add at GoDaddy only count if your domain uses GoDaddy's nameservers (the setting that tells the internet which company hosts your DNS). If your nameservers point somewhere else, such as your website host, add the records there instead.

Not sure what's set up already? Run your domain through our free SPF, DKIM and DMARC checker for a plain-English summary first.

How to add the Google Workspace SPF record on GoDaddy

SPF (Sender Policy Framework) is a list of the servers allowed to send email for your domain. If Google Workspace is the only thing that sends email as you, the value is v=spf1 include:_spf.google.com ~all.

  1. On the DNS page, select Add New Record, then choose TXT from the Type menu. If an SPF record already exists, select Edit next to it instead.

  2. In Name, enter @. This means your main domain, yourcompany.com.

  3. In Value, paste:

    v=spf1 include:_spf.google.com ~all
    
  4. Leave TTL at GoDaddy's default of 1 hour.

  5. Select Save. If your domain has Domain Protection, GoDaddy asks you to confirm with a code.

  6. If you edited an existing record, make sure no second v=spf1 record is left on the page.

If the existing record includes secureserver.net

secureserver.net is GoDaddy's email server. GoDaddy's help page says its own email products (such as Professional Email and Microsoft 365 from GoDaddy) and its Linux hosting use v=spf1 include:secureserver.net -all.

  • If you still send some email through GoDaddy (for example from a website hosted there), keep it and add Google. This matches the "Google Workspace and GoDaddy" example on Google's own setup page:

    v=spf1 include:_spf.google.com include:secureserver.net ~all
    
  • If all your email now goes through Google Workspace, replace the value with v=spf1 include:_spf.google.com ~all. Google advises removing services that no longer send email for you.

Either way, change -all to ~all. Google recommends ~all for Workspace.

For more on merging SPF records and the 10-lookup limit, see our guide to the SPF record for Google Workspace.

How to turn on DKIM for Google Workspace on GoDaddy

DKIM (DomainKeys Identified Mail) signs each email so receivers can tell it really came from your domain. You create the key in Google, paste it into GoDaddy, then switch it on in Google.

Part 1: Create the key in Google. You need to be a super administrator. Google says to wait 24–72 hours after turning on Gmail for a new account before you try this.

  1. In the Google Admin console, go to Menu → Apps → Google Workspace → Gmail.
  2. Click Authenticate email and choose your domain.
  3. Click Generate New Record, keep 2048 as the key length and google as the prefix selector, then click Generate.
  4. Copy the DNS Host name (usually google._domainkey) and the TXT record value (it starts with v=DKIM1). Don't click Start authentication yet.

Part 2: Add the key at GoDaddy.

  1. On the DNS page, select Add New Record, then TXT.
  2. In Name, enter google._domainkey.
  3. In Value, paste the whole key from Google, in one piece.
  4. Select Save.

GoDaddy accepts TXT values up to 1,024 characters, and Google's 2048-bit key fits within that. If GoDaddy shows an error anyway, Google's help says you can choose a 1024-bit key instead.

Part 3: Switch it on. Google says DKIM can take up to 48 hours to start working. Go back to Authenticate email and click Start authentication. When it's working, the status reads Authenticating email with DKIM.

Our guide to turning on DKIM in Google Workspace covers the Google side in more detail.

How to set up DMARC on GoDaddy

DMARC tells receiving servers what to do with email that uses your domain but fails SPF and DKIM, and sends you reports. Google says to have SPF and DKIM working for at least 48 hours first, and to start with p=none, which asks receivers to take no action and just report.

This matters more on GoDaddy than elsewhere. If your domain has GoDaddy's default quarantine policy and SPF or DKIM isn't set up yet, your Workspace email could be sent to spam. Getting SPF and DKIM in place quickly fixes that.

  1. Pick a mailbox or group for reports, such as dmarc-reports@yourcompany.com. Google advises against your own inbox, because reports can arrive daily from every service you email.

  2. On the DNS page, find the TXT record named _dmarc. If it's there, select Edit. If not, select Add New Record, then TXT.

  3. In Name, enter _dmarc.

  4. In Value, enter:

    v=DMARC1; p=none; rua=mailto:dmarc-reports@yourcompany.com
    
  5. Select Save, and check only one _dmarc record remains. Under the DMARC standard, if receivers find more than one, they skip DMARC entirely.

GoDaddy says you keep full control of its default record, so you can change it like any other. This follows Google's recommended rollout: start at p=none, check your reports, then move to p=quarantine once they show all your real email passing. Our DMARC guide for Google Workspace explains how to step up.

Check that all three are working

Give it a few hours, then test with a real email.

  1. Send an email from you@yourcompany.com to a personal Gmail address.
  2. Open it in Gmail on a computer, click More (the three dots) next to Reply, then Show original.
  3. You want to see PASS for SPF, DKIM and DMARC.

Then run your domain through our free domain checker again to confirm there's exactly one SPF record and one DMARC record. GoDaddy says most DNS changes take effect within an hour, but some can take up to 48 hours.

Common GoDaddy mistakes and how to fix them

Typed the full name

Name_dmarc.yourcompany.com

Your host adds .yourcompany.com

Resulting recordDoubled_dmarc.yourcompany.com.yourcompany.com

Typed only the first part

Name_dmarc

Your host adds .yourcompany.com

Resulting recordCorrect_dmarc.yourcompany.com
GoDaddy adds your domain for you. Type only the first part.
MistakeWhat happensFix
Two TXT records starting with v=spf1SPF fails for every emailMerge them into one
Full domain typed in Name (_dmarc.yourcompany.com)GoDaddy creates _dmarc.yourcompany.com.yourcompany.comEnter only _dmarc
-all left from GoDaddy's default SPFStricter than Google recommendsChange it to ~all
Second _dmarc record added next to GoDaddy's defaultReceivers ignore DMARCDelete one; keep a single record
DKIM key added but Start authentication never clickedEmail isn't signedClick it in the Admin console
Records added at GoDaddy, nameservers elsewhereRecords have no effectAdd them where your nameservers point

Setup won't keep a mail merge out of spam on its own

SPF, DKIM and DMARC prove your email really comes from you. Gmail requires SPF or DKIM from everyone who emails Gmail users, so you need them. But passing them doesn't decide where your email lands.

  • Your sending history. A new or quiet inbox that suddenly sends hundreds of emails looks risky. Warmuply warms up your Google Workspace inbox in the background and shows you a daily safe-send number: how many emails it can safely send today.
  • Who you email. Email people who expect to hear from you. Every "Report spam" click hurts your reputation, and Gmail asks senders to keep their spam rate in Postmaster Tools (Google's free dashboard for senders) below 0.10% and never reach 0.30%.
  • What your email says. Write like a one-to-one email, keep links to one or two, skip attachments, offer an easy way to opt out, and stop emailing anyone who asks.

For what filters look at in the email itself, see our guide to what really sends a mail merge to spam.

Warmup builds trust in your inbox. It can't make people want an email they didn't expect.

Before you hit send

  • Your GoDaddy DNS page has exactly one SPF record with include:_spf.google.com, and exactly one _dmarc record.
  • The Admin console says Authenticating email with DKIM.
  • A test email shows SPF, DKIM and DMARC as PASS under Show original.
  • Everyone on your list expects to hear from you, and your email gives them an easy way to opt out.

Check your domain for free

Frequently asked questions

Google says the Authenticate email page can keep showing that message for up to 48 hours after you generate a DKIM key. If you’ve added the google._domainkey record at GoDaddy and it matches the value in the Admin console, you can ignore the message. Click Start authentication once the record has had time to spread.

Yes, if your domain has GoDaddy’s Domain Protection. GoDaddy asks for extra identity checks before it saves DNS changes: a code from your 2-step verification if it has been on for at least 24 hours, or otherwise a one-time password sent to the email address on your GoDaddy account.

Add them wherever your nameservers point. Nameservers decide which company’s DNS settings the internet reads. GoDaddy says your domain must use GoDaddy nameservers for records added in your GoDaddy account to work, so if they point to another service, the records you add at GoDaddy are ignored.

Leave it at GoDaddy’s default of 1 hour. TTL (time to live) is how long other servers remember a record before checking it again. GoDaddy uses 1 hour unless you change it, and you don’t need anything different for SPF, DKIM or DMARC.

No. SPF, DKIM and DMARC are TXT records that describe your outgoing email. Incoming mail is routed by your MX records, which you set up when you connected Google Workspace. Adding or editing these three records doesn’t move your inbox or interrupt the email you receive.

Sources (11)

Check your SPF, DKIM and DMARC for free.

Our free checker reads your domain's public records and explains each result in plain English, with the exact text to paste.

We're launching soon

Get on the waitlist for an exclusive launch discount.

We'll only email you about the launch.