Google Workspace SPF on GoDaddy, plus DKIM and DMARC
The Warmuply TeamLast checked: October 2026
Your domain is with GoDaddy, your email runs on Google Workspace, and you're getting ready for your first mail merge. This guide shows you exactly how to set up the Google Workspace SPF record on GoDaddy, then DKIM and DMARC, with the values to paste and where each one goes on GoDaddy's DNS page.
It takes about 20 minutes of clicking, then up to 48 hours for everything to take effect. You'll need to sign in to both GoDaddy and the Google Admin console (the settings area for your Workspace account).
What you'll add to GoDaddy
You'll add or edit three TXT records (records that hold a line of text) on your domain's DNS page. DNS is the public address book for your domain, and GoDaddy hosts it if you bought your domain there.
| Setting | What it does | Type | Name in GoDaddy | Value |
|---|---|---|---|---|
| SPF | Lists the servers allowed to send email as you | TXT | @ | v=spf1 include:_spf.google.com ~all |
| DKIM | Adds a digital signature to every email you send | TXT | google._domainkey | The key you copy from Google |
| DMARC | Tells receivers what to do with email that fails the checks | TXT | _dmarc | v=DMARC1; p=none; rua=mailto:dmarc-reports@yourcompany.com |
DNS records for yourcompany.com
3 TXT recordsGoDaddy adds your domain to the Name for you. Type _dmarc, not _dmarc.yourcompany.com.
Before you start: check what's already on GoDaddy
Look before you add anything. Two things on GoDaddy commonly trip people up.
- Sign in to your GoDaddy Domain Portfolio and select your domain to open Domain Settings.
- Select DNS to see your records.
- Look for a TXT record whose value starts with
v=spf1. GoDaddy says only one SPF record works on a domain at a time, so if one exists, you'll edit it rather than add a second. - Look for a TXT record with the Name
_dmarc. Since April 2025, GoDaddy has added a default DMARC record with a "quarantine" policy to domains bought or transferred into GoDaddy. You'll edit this one too.
Records you add at GoDaddy only count if your domain uses GoDaddy's nameservers (the setting that tells the internet which company hosts your DNS). If your nameservers point somewhere else, such as your website host, add the records there instead.
Not sure what's set up already? Run your domain through our free SPF, DKIM and DMARC checker for a plain-English summary first.
How to add the Google Workspace SPF record on GoDaddy
SPF (Sender Policy Framework) is a list of the servers allowed to send email for your domain. If Google Workspace is the only thing that sends email as you, the value is v=spf1 include:_spf.google.com ~all.
-
On the DNS page, select Add New Record, then choose TXT from the Type menu. If an SPF record already exists, select Edit next to it instead.
-
In Name, enter
@. This means your main domain,yourcompany.com. -
In Value, paste:
v=spf1 include:_spf.google.com ~all -
Leave TTL at GoDaddy's default of 1 hour.
-
Select Save. If your domain has Domain Protection, GoDaddy asks you to confirm with a code.
-
If you edited an existing record, make sure no second
v=spf1record is left on the page.
If the existing record includes secureserver.net
secureserver.net is GoDaddy's email server. GoDaddy's help page says its own email products (such as Professional Email and Microsoft 365 from GoDaddy) and its Linux hosting use v=spf1 include:secureserver.net -all.
-
If you still send some email through GoDaddy (for example from a website hosted there), keep it and add Google. This matches the "Google Workspace and GoDaddy" example on Google's own setup page:
v=spf1 include:_spf.google.com include:secureserver.net ~all -
If all your email now goes through Google Workspace, replace the value with
v=spf1 include:_spf.google.com ~all. Google advises removing services that no longer send email for you.
Either way, change -all to ~all. Google recommends ~all for Workspace.
For more on merging SPF records and the 10-lookup limit, see our guide to the SPF record for Google Workspace.
How to turn on DKIM for Google Workspace on GoDaddy
DKIM (DomainKeys Identified Mail) signs each email so receivers can tell it really came from your domain. You create the key in Google, paste it into GoDaddy, then switch it on in Google.
Part 1: Create the key in Google. You need to be a super administrator. Google says to wait 24–72 hours after turning on Gmail for a new account before you try this.
- In the Google Admin console, go to Menu → Apps → Google Workspace → Gmail.
- Click Authenticate email and choose your domain.
- Click Generate New Record, keep 2048 as the key length and
googleas the prefix selector, then click Generate. - Copy the DNS Host name (usually
google._domainkey) and the TXT record value (it starts withv=DKIM1). Don't click Start authentication yet.
Part 2: Add the key at GoDaddy.
- On the DNS page, select Add New Record, then TXT.
- In Name, enter
google._domainkey. - In Value, paste the whole key from Google, in one piece.
- Select Save.
GoDaddy accepts TXT values up to 1,024 characters, and Google's 2048-bit key fits within that. If GoDaddy shows an error anyway, Google's help says you can choose a 1024-bit key instead.
Part 3: Switch it on. Google says DKIM can take up to 48 hours to start working. Go back to Authenticate email and click Start authentication. When it's working, the status reads Authenticating email with DKIM.
Our guide to turning on DKIM in Google Workspace covers the Google side in more detail.
How to set up DMARC on GoDaddy
DMARC tells receiving servers what to do with email that uses your domain but fails SPF and DKIM, and sends you reports. Google says to have SPF and DKIM working for at least 48 hours first, and to start with p=none, which asks receivers to take no action and just report.
This matters more on GoDaddy than elsewhere. If your domain has GoDaddy's default quarantine policy and SPF or DKIM isn't set up yet, your Workspace email could be sent to spam. Getting SPF and DKIM in place quickly fixes that.
-
Pick a mailbox or group for reports, such as
dmarc-reports@yourcompany.com. Google advises against your own inbox, because reports can arrive daily from every service you email. -
On the DNS page, find the TXT record named
_dmarc. If it's there, select Edit. If not, select Add New Record, then TXT. -
In Name, enter
_dmarc. -
In Value, enter:
v=DMARC1; p=none; rua=mailto:dmarc-reports@yourcompany.com -
Select Save, and check only one
_dmarcrecord remains. Under the DMARC standard, if receivers find more than one, they skip DMARC entirely.
GoDaddy says you keep full control of its default record, so you can change it like any other. This follows Google's recommended rollout: start at p=none, check your reports, then move to p=quarantine once they show all your real email passing. Our DMARC guide for Google Workspace explains how to step up.
Check that all three are working
Give it a few hours, then test with a real email.
- Send an email from
you@yourcompany.comto a personal Gmail address. - Open it in Gmail on a computer, click More (the three dots) next to Reply, then Show original.
- You want to see PASS for SPF, DKIM and DMARC.
Then run your domain through our free domain checker again to confirm there's exactly one SPF record and one DMARC record. GoDaddy says most DNS changes take effect within an hour, but some can take up to 48 hours.
Common GoDaddy mistakes and how to fix them
| Mistake | What happens | Fix |
|---|---|---|
Two TXT records starting with v=spf1 | SPF fails for every email | Merge them into one |
Full domain typed in Name (_dmarc.yourcompany.com) | GoDaddy creates _dmarc.yourcompany.com.yourcompany.com | Enter only _dmarc |
-all left from GoDaddy's default SPF | Stricter than Google recommends | Change it to ~all |
Second _dmarc record added next to GoDaddy's default | Receivers ignore DMARC | Delete one; keep a single record |
| DKIM key added but Start authentication never clicked | Email isn't signed | Click it in the Admin console |
| Records added at GoDaddy, nameservers elsewhere | Records have no effect | Add them where your nameservers point |
Setup won't keep a mail merge out of spam on its own
SPF, DKIM and DMARC prove your email really comes from you. Gmail requires SPF or DKIM from everyone who emails Gmail users, so you need them. But passing them doesn't decide where your email lands.
- Your sending history. A new or quiet inbox that suddenly sends hundreds of emails looks risky. Warmuply warms up your Google Workspace inbox in the background and shows you a daily safe-send number: how many emails it can safely send today.
- Who you email. Email people who expect to hear from you. Every "Report spam" click hurts your reputation, and Gmail asks senders to keep their spam rate in Postmaster Tools (Google's free dashboard for senders) below 0.10% and never reach 0.30%.
- What your email says. Write like a one-to-one email, keep links to one or two, skip attachments, offer an easy way to opt out, and stop emailing anyone who asks.
For what filters look at in the email itself, see our guide to what really sends a mail merge to spam.
Warmup builds trust in your inbox. It can't make people want an email they didn't expect.
Before you hit send
- Your GoDaddy DNS page has exactly one SPF record with
include:_spf.google.com, and exactly one_dmarcrecord.- The Admin console says Authenticating email with DKIM.
- A test email shows SPF, DKIM and DMARC as PASS under Show original.
- Everyone on your list expects to hear from you, and your email gives them an easy way to opt out.
Frequently asked questions
Google says the Authenticate email page can keep showing that message for up to 48 hours after you generate a DKIM key. If you’ve added the google._domainkey record at GoDaddy and it matches the value in the Admin console, you can ignore the message. Click Start authentication once the record has had time to spread.
Yes, if your domain has GoDaddy’s Domain Protection. GoDaddy asks for extra identity checks before it saves DNS changes: a code from your 2-step verification if it has been on for at least 24 hours, or otherwise a one-time password sent to the email address on your GoDaddy account.
Add them wherever your nameservers point. Nameservers decide which company’s DNS settings the internet reads. GoDaddy says your domain must use GoDaddy nameservers for records added in your GoDaddy account to work, so if they point to another service, the records you add at GoDaddy are ignored.
Leave it at GoDaddy’s default of 1 hour. TTL (time to live) is how long other servers remember a record before checking it again. GoDaddy uses 1 hour unless you change it, and you don’t need anything different for SPF, DKIM or DMARC.
No. SPF, DKIM and DMARC are TXT records that describe your outgoing email. Incoming mail is routed by your MX records, which you set up when you connected Google Workspace. Adding or editing these three records doesn’t move your inbox or interrupt the email you receive.
Sources (11)
- Set up SPF (Google Workspace Help) (checked October 2026)
- Set up DKIM (Google Workspace Help) (checked October 2026)
- Troubleshoot DKIM issues (Google Workspace Help) (checked October 2026)
- Set up DMARC (Google Workspace Help) (checked October 2026)
- Troubleshoot DMARC issues (Google Workspace Help) (checked October 2026)
- Email sender guidelines (Gmail Help) (checked October 2026)
- Add a TXT record (GoDaddy Help) (checked October 2026)
- Edit a TXT record (GoDaddy Help) (checked October 2026)
- Add an SPF record (GoDaddy Help) (checked October 2026)
- Enhancing domain security: GoDaddy’s commitment to DMARC implementation (GoDaddy Blog) (checked October 2026)
- RFC 7489: Domain-based Message Authentication, Reporting, and Conformance (DMARC) (checked October 2026)
Related guides
- Check SPF, DKIM and DMARC: Free Plain-English CheckerTo check SPF, DKIM and DMARC, enter your domain in the free checker on this page. It reads your domain’s public DNS records and shows…Read the guide
- SPF Record for Google Workspace: Copy-Paste Setup GuideThe SPF record for Google Workspace is v=spf1 include:_spf.google.com ~all. Add it as a TXT record at your domain host, with the host set to…Read the guide
- DKIM for Google Workspace: How to Turn It On, Step by StepTo turn on DKIM for Google Workspace, sign in to the Admin console as a super admin and go to Apps > Google Workspace >…Read the guide
Check your SPF, DKIM and DMARC for free.
Our free checker reads your domain's public records and explains each result in plain English, with the exact text to paste.