DKIM for Google Workspace: How to Turn It On, Step by Step
The Warmuply TeamLast checked: October 2026
Turning on DKIM for Google Workspace takes three steps: you create a key in Google, add it to your domain, then switch it on. It's one of the settings Gmail, Outlook and Yahoo check to decide whether your email is really from you, and it matters most before your first mail merge.
This guide walks you through each step, shows you how to check it worked, and covers the fixes for the most common problem: Google Workspace DKIM not authenticating. Set aside about 15 minutes of work, plus some waiting time while the change takes effect.
Do you need DKIM for Google Workspace?
Yes. DKIM (DomainKeys Identified Mail) adds a digital signature to every email you send. Receiving servers check that signature against a public key on your domain. If it matches, they know the email came from your domain and wasn't changed on the way.
Google's rules for sending to personal Gmail accounts work like this:
- All senders must set up SPF or DKIM.
- Anyone sending more than 5,000 messages a day to Gmail accounts must set up SPF, DKIM and DMARC.
- Google recommends all three for every domain, whatever your volume.
DKIM also matters for DMARC, the setting that tells receivers what to do with email that fails these checks. To pass DMARC, the domain that signs or sends the email has to match the domain in your From address. Turning on your own DKIM key means your email is signed as yourcompany.com.
If you'd like the bigger picture first, read our plain-English guide to SPF, DKIM and DMARC.
What you need before you start
DKIM in three steps
- up to 48 hours
Check these four things first, so nothing stops you halfway through.
| You need | Why |
|---|---|
| A super admin sign-in for Google Workspace | Google only lets super admins generate the DKIM key. |
| Gmail turned on for at least 24–72 hours | Google says that if you try sooner, you may get an error that the DKIM record was not created. |
| Access to your domain host | Your domain host is the company where you manage your domain's settings, usually where you bought it. You'll add a record there. |
| About 15 minutes, then patience | DKIM can take up to 48 hours to start working after you add the key. |
Is DKIM already set up? It might be. Google says your domain may already have DKIM if you bought it from a Google partner when you signed up, or if your domain came with DKIM set up by default. Run our free SPF, DKIM and DMARC checker to find out before you start.
On Squarespace? Google says Squarespace creates and adds the DKIM key for you. Skip to Step 3.
Step 1: How do you generate your DKIM key in the Admin console?
You create the key in the Google Admin console, the dashboard where you manage your Google Workspace account.
- Sign in to the Google Admin console as a super admin.
- Go to Menu > Apps > Google Workspace > Gmail.
- Click Authenticate email.
- In the Selected domain menu, pick the domain you send from.
- Click Generate New Record.
- Choose your settings:
- DKIM key bit length: choose 2048. Google recommends it because longer keys are more secure. Pick 1024 only if your domain host can't store a 2048-bit key.
- Prefix selector: leave it as google, the default Google recommends. Change it only if your domain already has a DKIM key that uses the prefix "google".
- Click Generate.
Google then shows two values. Keep this page open, because you'll copy both into your domain host:
- DNS Host name (TXT record name). Usually
google._domainkey. - TXT record value. A long string that starts with
v=DKIM1. This is your public key.
You may also see a message saying "You must update the DNS records for this domain". That's expected at this stage. Don't click Start authentication yet.
Step 2: How do you add the DKIM record at your domain host?
You add the key as a TXT record, which is a plain-text note attached to your domain's DNS (the public set of records that tells the internet how your domain works).
- Sign in to your domain host.
- Open the DNS settings for your domain. It may be called "DNS", "Manage DNS" or "Advanced DNS".
- Add a new record and choose TXT as the type.
- Fill in the fields as shown below.
- Save the record.
| Field (your host may call it…) | What to enter |
|---|---|
| Type | TXT |
| Host, Name, Hostname or Alias | The DNS host name from Google, usually google._domainkey |
| Value, Content, Data or Text | The full TXT record value from Google, starting v=DKIM1 |
Two values to copy
The value will look something like this, but much longer. Copy yours from the Admin console, never from an example:
v=DKIM1; k=rsa; p=[the long key shown in your Admin console]
A few things to watch:
- Copy the whole key. A missing character at the start or end breaks it.
- Check what your host adds to the Host field. Some hosts add your domain to whatever you type automatically. Your host's help page will say whether to enter just
google._domainkey. - If the record won't save, your host may limit TXT records to 255 characters. See the fixes further down.
- Sending from more than one domain? Repeat Steps 1 to 3 for each one. Google gives every domain its own key.
Then wait. Google says it can take up to 48 hours for DKIM to start working after you add the key.
Step 3: How do you turn on DKIM authentication?
Once your record has had time to take effect, go back to the Admin console and switch DKIM on.
- Go to Menu > Apps > Google Workspace > Gmail > Authenticate email.
- Select the same domain in the Selected domain menu.
- Click Start authentication.
When it's working, the status at the top of the page changes to Authenticating email with DKIM. If Google can't find your record yet, wait a few more hours and try again.
How do you check that DKIM is working?
Send a real test email to a different inbox. Google notes you can't check DKIM by emailing yourself.
- From your Workspace address, send an email to a personal Gmail account you can open.
- Open the email in Gmail on a computer.
- Next to Reply, click More (the three dots), then Show original.
- In the header text, find the line that starts
Authentication-Results.
Full message header
SimplifiedYou want to see dkim=pass with your own domain, yourcompany.com. Google says other email services format this differently, so you may see DKIM=OK elsewhere.
On the Gmail app for Android, you can also tap View details, then View security details. A "Signed by" line showing your domain means the message is signed.
If there's no DKIM line at all, your email isn't being signed yet. Check that you clicked Start authentication and work through the fixes below.
Google Workspace DKIM not authenticating? Common fixes
Most problems come down to a step that was skipped, a value that was cut short, or not waiting long enough.
| What you see | Likely cause | What to do |
|---|---|---|
| Status says Not authenticating | DKIM isn't switched on yet | Go back to Authenticate email and click Start authentication. |
| "You must update the DNS records for this domain" | The record hasn't taken effect, or isn't there | Google says this can show for up to 48 hours. If your record is added correctly, you can ignore it. |
| An error that the DKIM record was not created | Gmail was turned on less than 24–72 hours ago | Wait, then generate the key again. |
| Your host won't accept the value | Your host limits TXT records to 255 characters | Split the key into parts (below), switch to a 1024-bit key, or ask your host whether it supports longer records. |
| Host name and value are blank in the Admin console | No key has been generated | Go back to Step 1. |
dkim=fail with "body hash did not verify" | Something changed the email after it was sent | If you use an outbound gateway (a service that processes outgoing mail, for example to add a footer), make sure it doesn't edit messages. |
Splitting a long key. A 2048-bit key won't fit in one 255-character string. Google's fix is to split the key into chunks, put each chunk in its own quotation marks, and enter them one after another in the Value field:
"v=DKIM1; k=rsa; p=[first part of your key]" "[second part of your key]"
Keep every character, in the same order, with nothing added or removed.
Check the record directly. Open Google's free Dig tool (opens in a new tab), choose TXT, and look up google._domainkey.yourcompany.com (with your own domain). Compare the result with the value in your Admin console. Every character should match, in order. If nothing comes back, the record isn't published under that name yet.
DKIM passes, but your email still goes to spam
That can happen. DKIM proves who sent the email. It doesn't make anyone want to receive it.
Google's own troubleshooting points to sending practices when DKIM is set up correctly but mail still lands in spam. The things only you control matter most here:
- Who you email. Write to people who expect to hear from you. Old, bought or scraped lists bring bounces and spam complaints.
- Spam complaints. Each "Report spam" click hurts your reputation. Google asks senders to keep their spam rate in Postmaster Tools (its free sender dashboard) below 0.3%, and ideally below 0.1%.
- What the email says. Write like a one-to-one email, keep links to one or two, skip attachments, and give people an easy way to opt out.
Our guide to spam trigger words covers the wording side in more detail.
Upgrading from a 1024-bit key
Generate the new 2048-bit key with a new selector prefix (for example google2048) instead of replacing the google record. Add the new TXT record at your domain host, wait until the checker finds it, then click Start authentication. Remove the old google record a few days later. This avoids a gap where your email isn't signed.
A 2048-bit record is longer than 255 characters. Most domain hosts split it automatically, but some need it pasted as two quoted strings: see Splitting a long key under common fixes.
What should you set up after DKIM?
DKIM is one of three settings that prove your email is really from you. If you haven't done the other two, do them next.
Make sure your SPF record includes Google with our guide to setting up SPF for Google Workspace.
Then add DMARC, which tells receivers what to do with email that fails these checks and can send you reports, with our guide to setting up DMARC for Google Workspace.
These settings prove who you are, but they don't build trust on their own. A new or quiet inbox also needs a sending history before a mail merge. Warmuply warms up your inbox in the background and shows you how many emails you can safely send each day.
Before you hit send
- The Admin console shows Authenticating email with DKIM for every domain you send from.
- A test email to a personal Gmail account shows
dkim=passwith your domain.- Everyone on your list expects to hear from you, and every email has an easy way to opt out.
Not sure about your setup? Paste your domain into our free checker for a plain-English answer.
Frequently asked questions
Yes, set up both. Google asks every sender to personal Gmail accounts to use SPF or DKIM, and anyone sending more than 5,000 messages a day to use both, plus DMARC. Google recommends both for everyone: DKIM shows the email really came from your domain and wasn’t changed, while SPF shows it came from an allowed server.
Yes. YAMM’s help center says DKIM and DMARC on your domain apply to YAMM because it sends through your Gmail account. Gmail’s built-in mail merge sends from Gmail itself. So once DKIM is on for your domain, your mail merges are signed too. There’s nothing to set up inside the tool.
Yes, it’s shorter. Google says that if Squarespace is your domain provider, the DKIM key is created and added to your DNS records for you. Skip straight to Step 3: open Authenticate email in the Admin console, select your domain and click Start authentication. Then send a test email to check it.
Yes. Google says each domain needs its own unique DKIM key from the Admin console, so repeat all three steps for every domain you send from. YAMM also notes that mail sent from an alias domain without DKIM is more likely to be marked as spam.
Choose 2048-bit if your domain host supports it. Google recommends it because longer keys are more secure. Gmail needs a key of at least 1024 bits to accept your email as signed, so 1024-bit is a fallback if your host can’t store the longer key, not a requirement.
Not in the email itself. DKIM adds a hidden signature to each message’s header. In Gmail, a recipient who checks the message details may see your domain listed as ‘Signed by’, which shows the message is authenticated. Your emails look exactly the same.
Sources (8)
- Set up DKIM (checked October 2026)
- Troubleshoot DKIM issues (checked October 2026)
- About authentication methods (checked October 2026)
- About TXT records (checked October 2026)
- Email sender guidelines (checked October 2026)
- Trace an email with its full header (checked October 2026)
- Check if your Gmail message is authenticated (checked October 2026)
- Account, delivery, scheduling (YAMM help center) (checked October 2026)
Related guides
- SPF, DKIM and DMARC Explained in Plain EnglishHere are SPF, DKIM and DMARC explained simply. SPF lists the servers allowed to send email for your domain. DKIM adds a digital signature that…Read the guide
- Check SPF, DKIM and DMARC: Free Plain-English CheckerTo check SPF, DKIM and DMARC, enter your domain in the free checker on this page. It reads your domain’s public DNS records and shows…Read the guide
- Spam Trigger Words: What Really Sends Email to SpamSpam trigger words like “FREE”, “act now” and “risk-free” rarely send an email to spam on their own. Filters care more about who you email…Read the guide
Check your SPF, DKIM and DMARC for free.
Our free checker reads your domain's public records and explains each result in plain English, with the exact text to paste.