DMARC for Google Workspace: Setup Guide (Start at p=none)
The Warmuply TeamLast checked: October 2026
DMARC is the third of three settings that prove your email really comes from you. It tells Gmail, Outlook and Yahoo what to do with email that uses your domain but fails the checks, and it sends you reports on who is sending email as you.
This guide covers DMARC for Google Workspace: the exact record to copy, where it goes, how to check it works, and why to start with p=none. It takes about ten minutes, and you don't need to be technical.
What does DMARC do?
DMARC (Domain-based Message Authentication, Reporting and Conformance) is one line of text you publish on your domain. It does two jobs:
- It sets a policy. When an email uses your domain but fails the checks, your policy asks the receiving server to deliver it anyway, send it to spam, or reject it.
- It asks for reports. Mail services that receive your email send you summaries of what passed and failed.
An email passes DMARC when SPF or DKIM passes and the domain that passed matches the domain in the From address. This match is called alignment. If you send from you@yourcompany.com, SPF or DKIM has to pass for yourcompany.com. One of the two is enough.
When an email passes DMARC
- or
For the bigger picture of how the three settings fit together, read our plain-English guide to SPF, DKIM and DMARC.
Are SPF and DKIM set up first?
Set up SPF and DKIM before DMARC, then wait 48 hours. Google says skipping this step will probably cause delivery problems, and that SPF and DKIM should run for at least 48 hours before you add DMARC.
- SPF (Sender Policy Framework) is a published list of the servers allowed to send email for your domain.
- DKIM (DomainKeys Identified Mail) adds a digital signature to each email, so receivers can tell it really came from your domain.
Our step-by-step guide to the SPF record for Google Workspace has the exact record to paste.
Our guide to turning on DKIM in Google Workspace walks you through it step by step.
Not sure where you stand? Enter your domain in our free SPF, DKIM and DMARC checker. It also shows whether a DMARC record already exists.
Do other services send email as you? Think invoicing tools, help desks or website contact forms. Google says each one must pass SPF and DKIM for your domain too, and their help pages explain how.
What's the DMARC record for Google Workspace?
Here's the record to start with. Change only the email address, to the one that should receive your reports:
v=DMARC1; p=none; rua=mailto:dmarc-reports@yourcompany.com
The starter DMARC record
v=DMARC1;p=none;rua=mailto:dmarc-reports@yourcompany.com
| Part | What it means |
|---|---|
v=DMARC1 | "This is a DMARC record." It must come first. |
p=none | The policy: take no action on email that fails, just report it. It must come second. |
rua=mailto:… | Where to send daily reports. The mailto: in front of the address is required. |
Choose a reports address before you publish. Every mail service that receives your email can send a report each day, so Google advises against using your own inbox. Set up a separate mailbox or a group, such as dmarc-reports@yourcompany.com, or use a service that reads DMARC reports for you. Keep the address on the same domain as the record; a different domain needs an extra step (see the FAQ).
Why start with p=none?
Start with p=none because it gives you reports with no risk to your email. Google says that under p=none, messages are delivered normally and can't be rejected or sent to spam because of DMARC.
A stricter policy applies to every email that uses your domain, not only your mail merge. Say your accounting tool sends invoices as billing@yourcompany.com and you forgot to set it up. Under p=quarantine those invoices could land in spam. Under p=none they arrive as usual, and your reports show you the gap.
| Policy | What receivers are asked to do with email that fails | When to use it |
|---|---|---|
p=none | Deliver it as normal, and report it | First, while you read your reports |
p=quarantine | Send it to the spam folder | Once reports show all your real email passes |
p=reject | Refuse it | Optional, after quarantine has run cleanly |
p=none also meets the big mailbox providers' rules for bulk senders:
- Gmail requires DMARC if you send more than 5,000 messages a day to Gmail accounts, and says the policy can be none.
- Yahoo requires bulk senders to publish at least
p=none, and the email must pass DMARC. - Outlook.com requires domains sending more than 5,000 emails a day to have at least
p=none, aligned with SPF or DKIM. Since May 2025 it rejects email that doesn't meet this.
How do you add the DMARC record at your domain host?
You add the record at your domain host, the company where you manage your domain's settings, usually where you bought it. Nothing changes in the Google Admin console.
- Sign in to your domain host.
- Open the DNS settings for your domain. DNS (Domain Name System) is the set of public records attached to your domain. Your host may call this page "DNS", "Manage DNS" or "Advanced DNS".
- Look for an existing TXT record with the host name
_dmarc. If you find one, edit it instead of adding a second. - Add a new TXT record using the values in the table below.
- Save the record. Leave the TTL (how long other servers remember the record) at your host's default.
- Check the saved host name. Google notes that some hosts add your domain automatically, so make sure it reads
_dmarc.yourcompany.comand not_dmarc.yourcompany.com.yourcompany.com.
| Field (your host may call it…) | What to enter |
|---|---|
| Type | TXT |
| Host, Name, Hostname or Alias | _dmarc (or _dmarc.yourcompany.com if your host asks for the full name) |
| Value, Content, Data or Text | v=DMARC1; p=none; rua=mailto:dmarc-reports@yourcompany.com |
Keep exactly one DMARC record per domain. Under the DMARC standard, if receivers find more than one, they ignore them all. Each domain you send from needs its own record.
How do you check that DMARC is working?
Wait a few hours after saving, then check in two ways.
1. Check the record exists. Use our free checker or Google's free Check MX tool (opens in a new tab). Both look up your DMARC record and flag problems.
2. Check a real email passes.
- Send an email from your Workspace address to a personal Gmail account you can open.
- Open it in Gmail on a computer.
- Next to Reply, click More (the three dots), then Show original.
- In the header text, find the line that starts
Authentication-Results. A working setup showsdmarc=pass.
If the header is hard to read, click Copy to clipboard and paste it into Google's free Messageheader tool (opens in a new tab), which lays out the results for you.
Repeat the test with one email sent from your mail merge tool. If you see dmarc=fail, neither SPF nor DKIM passed for your domain, so fix those first.
What do DMARC reports tell you?
Reports show which servers send email as your domain, and how many messages passed or failed. They usually arrive daily from each service as XML files, a data format that's hard to read by eye.
Google recommends a third-party DMARC reporting service to collect and read them. In your first week, look for three things:
- Google Workspace passing. Expected, if SPF and DKIM are set up.
- Other services you use failing. Fix their SPF or DKIM before you tighten your policy.
- Servers you don't recognize failing. These may be people pretending to be you. Blocking them is what
quarantineandrejectare for.
DMARC record examples: from p=none to p=reject
Google recommends running p=none for at least a week while you read your reports, then moving to quarantine gradually.
Roll out DMARC in steps
Step 1: monitor.
v=DMARC1; p=none; rua=mailto:dmarc-reports@yourcompany.com
Step 2: quarantine. Google's example applies quarantine to a small share of failing email first, using pct (the percentage).
v=DMARC1; p=quarantine; pct=10; rua=mailto:dmarc-reports@yourcompany.com
Then raise the percentage until the policy covers all failing email, which is the same as leaving pct out:
v=DMARC1; p=quarantine; rua=mailto:dmarc-reports@yourcompany.com
A note on pct. The newest DMARC standard, RFC 9989 (May 2026), retires pct in favor of a test flag, t=y, though Google's help still uses pct. So don't count on every receiver honoring it. If your reports have been clean for a week or two, you can go straight from none to the full quarantine record.
Step 3 (optional): reject.
v=DMARC1; p=reject; rua=mailto:dmarc-reports@yourcompany.com
Think twice before this step. The DMARC standard warns that p=reject can break email forwarded through mailing lists and forwarding addresses. For many small teams, quarantine gives the protection without that risk.
Common DMARC mistakes (and the fix for each)
| Mistake | Fix |
|---|---|
| Two DMARC records on the same domain | Merge them into one. |
Adding the record with @ as the host name | The host name must be _dmarc. |
| Domain added twice to the host name | Enter just _dmarc if your host adds the domain for you. |
rua= without mailto: in front of the address | Write rua=mailto:dmarc-reports@yourcompany.com. |
Starting with p=reject copied from another site | Start with p=none and step up. |
Adding a ruf tag for detailed failure reports | Leave it out. Gmail doesn't send these. |
Will DMARC keep your mail merge out of spam?
Not on its own. DMARC proves your email really comes from you; it doesn't make anyone want it. Google's troubleshooting page says that if your policy is p=none and your email still lands in spam, the cause is probably something else.
Three other things matter just as much:
- Your sending history. A new or quiet inbox that suddenly sends hundreds of emails looks risky, and Google advises avoiding sudden spikes. Warmuply warms up your Google Workspace inbox in the background and shows you how many emails you can safely send each day.
- Who you email. Email people who expect to hear from you. "Report spam" clicks hurt your reputation fast, and Gmail asks senders to keep their spam rate below 0.1% and never reach 0.3%.
- What your email says. Write it like a one-to-one email, keep links to one or two, skip attachments, offer an easy way to opt out, and stop emailing anyone who asks.
For more on wording and complaints, see our guide to what really sends a mail merge to spam.
Warmup builds trust in your inbox. It can't make people want an email they didn't expect.
Before you hit send
- One DMARC record at
_dmarc.yourcompany.com, set top=none, with a reports address you check.- A test email from your mail merge tool shows
dmarc=passunder Show original.- Every service that sends email as your domain passes SPF or DKIM.
- Everyone on your list expects to hear from you, and can easily opt out.
Not sure about your setup? Our free checker gives you a plain-English answer.
Frequently asked questions
Gmail only requires DMARC from senders of more than 5,000 messages a day to Gmail accounts, but Google recommends SPF, DKIM and DMARC for every domain. Yahoo also urges every sender to publish a DMARC policy. A p=none record takes ten minutes and doesn’t change how your email is delivered, so there’s little reason to wait.
No. Google says that under p=none your messages are delivered normally, with no risk of being rejected or sent to spam because of DMARC. The DMARC standard says a none policy must not change how receivers handle your mail. You just start getting reports.
No. Google says you don’t need to do anything in the Admin console for DMARC. You publish the record at your domain host, the company where you manage your domain’s settings, and that’s the only place it needs to go.
Yes, but the other domain has to agree to receive them. Google says to add a TXT record at the other domain with the host name yourcompany.com._report._dmarc.[the other domain] and the value v=DMARC1;. Without it, receivers won’t send reports there. Using an address on your own domain avoids this step.
Not usually. Subdomains follow the policy on your main domain’s record unless you add an sp tag to set a different policy for them. A separate domain is different: yourcompany.co or a second brand domain needs its own DMARC record.
It means Gmail refused your email because it failed DMARC and your domain’s policy asked for that. Check that SPF and DKIM pass for the service that sent it, and that they pass for the same domain as your From address. Google lists this error on its DMARC troubleshooting page.
Sources (10)
- Set up DMARC (checked October 2026)
- Recommended DMARC rollout (checked October 2026)
- About DMARC reports (checked October 2026)
- Troubleshoot DMARC issues (checked October 2026)
- Email sender guidelines (checked October 2026)
- Trace an email with its full header (checked October 2026)
- Sender Requirements & Recommendations (Yahoo Sender Hub) (checked October 2026)
- Strengthening Email Ecosystem: Outlook’s New Requirements for High-Volume Senders (checked October 2026)
- RFC 9989: Domain-Based Message Authentication, Reporting, and Conformance (DMARC) (checked October 2026)
- RFC 7489: Domain-based Message Authentication, Reporting, and Conformance (DMARC) (checked October 2026)
Related guides
- SPF, DKIM and DMARC Explained in Plain EnglishHere are SPF, DKIM and DMARC explained simply. SPF lists the servers allowed to send email for your domain. DKIM adds a digital signature that…Read the guide
- SPF Record for Google Workspace: Copy-Paste Setup GuideThe SPF record for Google Workspace is v=spf1 include:_spf.google.com ~all. Add it as a TXT record at your domain host, with the host set to…Read the guide
- DKIM for Google Workspace: How to Turn It On, Step by StepTo turn on DKIM for Google Workspace, sign in to the Admin console as a super admin and go to Apps > Google Workspace >…Read the guide
Check your SPF, DKIM and DMARC for free.
Our free checker reads your domain's public records and explains each result in plain English, with the exact text to paste.