Skip to content
Warmuply

DMARC for Google Workspace: Setup Guide (Start at p=none)

The Warmuply TeamLast checked: October 2026

DMARC is the third of three settings that prove your email really comes from you. It tells Gmail, Outlook and Yahoo what to do with email that uses your domain but fails the checks, and it sends you reports on who is sending email as you.

This guide covers DMARC for Google Workspace: the exact record to copy, where it goes, how to check it works, and why to start with p=none. It takes about ten minutes, and you don't need to be technical.

What does DMARC do?

DMARC (Domain-based Message Authentication, Reporting and Conformance) is one line of text you publish on your domain. It does two jobs:

  1. It sets a policy. When an email uses your domain but fails the checks, your policy asks the receiving server to deliver it anyway, send it to spam, or reject it.
  2. It asks for reports. Mail services that receive your email send you summaries of what passed and failed.

An email passes DMARC when SPF or DKIM passes and the domain that passed matches the domain in the From address. This match is called alignment. If you send from you@yourcompany.com, SPF or DKIM has to pass for yourcompany.com. One of the two is enough.

When an email passes DMARC

From:you@yourcompany.com
  1. SPF passed for yourcompany.com?

  2. or

    DKIM passed for yourcompany.com?

At least one yes→ DMARC pass

The domain that passed must match the From address.

One match is enough. SPF or DKIM has to pass for the same domain you send from.

For the bigger picture of how the three settings fit together, read our plain-English guide to SPF, DKIM and DMARC.

Are SPF and DKIM set up first?

Set up SPF and DKIM before DMARC, then wait 48 hours. Google says skipping this step will probably cause delivery problems, and that SPF and DKIM should run for at least 48 hours before you add DMARC.

  • SPF (Sender Policy Framework) is a published list of the servers allowed to send email for your domain.
  • DKIM (DomainKeys Identified Mail) adds a digital signature to each email, so receivers can tell it really came from your domain.

Our step-by-step guide to the SPF record for Google Workspace has the exact record to paste.

Our guide to turning on DKIM in Google Workspace walks you through it step by step.

Not sure where you stand? Enter your domain in our free SPF, DKIM and DMARC checker. It also shows whether a DMARC record already exists.

Do other services send email as you? Think invoicing tools, help desks or website contact forms. Google says each one must pass SPF and DKIM for your domain too, and their help pages explain how.

What's the DMARC record for Google Workspace?

Here's the record to start with. Change only the email address, to the one that should receive your reports:

v=DMARC1; p=none; rua=mailto:dmarc-reports@yourcompany.com

The starter DMARC record

v=DMARC1;p=none;rua=mailto:dmarc-reports@yourcompany.com

  1. 1This is a DMARC record
  2. 2Don’t block anything yet
  3. 3Send daily reports here
Change only the email address. Keep everything else exactly as written.
PartWhat it means
v=DMARC1"This is a DMARC record." It must come first.
p=noneThe policy: take no action on email that fails, just report it. It must come second.
rua=mailto:…Where to send daily reports. The mailto: in front of the address is required.

Choose a reports address before you publish. Every mail service that receives your email can send a report each day, so Google advises against using your own inbox. Set up a separate mailbox or a group, such as dmarc-reports@yourcompany.com, or use a service that reads DMARC reports for you. Keep the address on the same domain as the record; a different domain needs an extra step (see the FAQ).

Why start with p=none?

Start with p=none because it gives you reports with no risk to your email. Google says that under p=none, messages are delivered normally and can't be rejected or sent to spam because of DMARC.

A stricter policy applies to every email that uses your domain, not only your mail merge. Say your accounting tool sends invoices as billing@yourcompany.com and you forgot to set it up. Under p=quarantine those invoices could land in spam. Under p=none they arrive as usual, and your reports show you the gap.

PolicyWhat receivers are asked to do with email that failsWhen to use it
p=noneDeliver it as normal, and report itFirst, while you read your reports
p=quarantineSend it to the spam folderOnce reports show all your real email passes
p=rejectRefuse itOptional, after quarantine has run cleanly

p=none also meets the big mailbox providers' rules for bulk senders:

  • Gmail requires DMARC if you send more than 5,000 messages a day to Gmail accounts, and says the policy can be none.
  • Yahoo requires bulk senders to publish at least p=none, and the email must pass DMARC.
  • Outlook.com requires domains sending more than 5,000 emails a day to have at least p=none, aligned with SPF or DKIM. Since May 2025 it rejects email that doesn't meet this.

How do you add the DMARC record at your domain host?

You add the record at your domain host, the company where you manage your domain's settings, usually where you bought it. Nothing changes in the Google Admin console.

  1. Sign in to your domain host.
  2. Open the DNS settings for your domain. DNS (Domain Name System) is the set of public records attached to your domain. Your host may call this page "DNS", "Manage DNS" or "Advanced DNS".
  3. Look for an existing TXT record with the host name _dmarc. If you find one, edit it instead of adding a second.
  4. Add a new TXT record using the values in the table below.
  5. Save the record. Leave the TTL (how long other servers remember the record) at your host's default.
  6. Check the saved host name. Google notes that some hosts add your domain automatically, so make sure it reads _dmarc.yourcompany.com and not _dmarc.yourcompany.com.yourcompany.com.
Field (your host may call it…)What to enter
TypeTXT
Host, Name, Hostname or Alias_dmarc (or _dmarc.yourcompany.com if your host asks for the full name)
Value, Content, Data or Textv=DMARC1; p=none; rua=mailto:dmarc-reports@yourcompany.com

Keep exactly one DMARC record per domain. Under the DMARC standard, if receivers find more than one, they ignore them all. Each domain you send from needs its own record.

How do you check that DMARC is working?

Wait a few hours after saving, then check in two ways.

1. Check the record exists. Use our free checker or Google's free Check MX tool (opens in a new tab). Both look up your DMARC record and flag problems.

2. Check a real email passes.

  1. Send an email from your Workspace address to a personal Gmail account you can open.
  2. Open it in Gmail on a computer.
  3. Next to Reply, click More (the three dots), then Show original.
  4. In the header text, find the line that starts Authentication-Results. A working setup shows dmarc=pass.

If the header is hard to read, click Copy to clipboard and paste it into Google's free Messageheader tool (opens in a new tab), which lays out the results for you.

Repeat the test with one email sent from your mail merge tool. If you see dmarc=fail, neither SPF nor DKIM passed for your domain, so fix those first.

What do DMARC reports tell you?

Reports show which servers send email as your domain, and how many messages passed or failed. They usually arrive daily from each service as XML files, a data format that's hard to read by eye.

Google recommends a third-party DMARC reporting service to collect and read them. In your first week, look for three things:

  • Google Workspace passing. Expected, if SPF and DKIM are set up.
  • Other services you use failing. Fix their SPF or DKIM before you tighten your policy.
  • Servers you don't recognize failing. These may be people pretending to be you. Blocking them is what quarantine and reject are for.

DMARC record examples: from p=none to p=reject

Google recommends running p=none for at least a week while you read your reports, then moving to quarantine gradually.

Roll out DMARC in steps

  1. 1Start here
    p=none

    Watch and report

    At least a week

  2. 2
    p=quarantine

    Failing email goes to spam

  3. 3Optional
    p=reject

    Failing email is refused

Read your reports before each step up

Move up one step at a time, and only when your reports are clean.

Step 1: monitor.

v=DMARC1; p=none; rua=mailto:dmarc-reports@yourcompany.com

Step 2: quarantine. Google's example applies quarantine to a small share of failing email first, using pct (the percentage).

v=DMARC1; p=quarantine; pct=10; rua=mailto:dmarc-reports@yourcompany.com

Then raise the percentage until the policy covers all failing email, which is the same as leaving pct out:

v=DMARC1; p=quarantine; rua=mailto:dmarc-reports@yourcompany.com

A note on pct. The newest DMARC standard, RFC 9989 (May 2026), retires pct in favor of a test flag, t=y, though Google's help still uses pct. So don't count on every receiver honoring it. If your reports have been clean for a week or two, you can go straight from none to the full quarantine record.

Step 3 (optional): reject.

v=DMARC1; p=reject; rua=mailto:dmarc-reports@yourcompany.com

Think twice before this step. The DMARC standard warns that p=reject can break email forwarded through mailing lists and forwarding addresses. For many small teams, quarantine gives the protection without that risk.

Common DMARC mistakes (and the fix for each)

MistakeFix
Two DMARC records on the same domainMerge them into one.
Adding the record with @ as the host nameThe host name must be _dmarc.
Domain added twice to the host nameEnter just _dmarc if your host adds the domain for you.
rua= without mailto: in front of the addressWrite rua=mailto:dmarc-reports@yourcompany.com.
Starting with p=reject copied from another siteStart with p=none and step up.
Adding a ruf tag for detailed failure reportsLeave it out. Gmail doesn't send these.

Will DMARC keep your mail merge out of spam?

Not on its own. DMARC proves your email really comes from you; it doesn't make anyone want it. Google's troubleshooting page says that if your policy is p=none and your email still lands in spam, the cause is probably something else.

Three other things matter just as much:

  • Your sending history. A new or quiet inbox that suddenly sends hundreds of emails looks risky, and Google advises avoiding sudden spikes. Warmuply warms up your Google Workspace inbox in the background and shows you how many emails you can safely send each day.
  • Who you email. Email people who expect to hear from you. "Report spam" clicks hurt your reputation fast, and Gmail asks senders to keep their spam rate below 0.1% and never reach 0.3%.
  • What your email says. Write it like a one-to-one email, keep links to one or two, skip attachments, offer an easy way to opt out, and stop emailing anyone who asks.

For more on wording and complaints, see our guide to what really sends a mail merge to spam.

Warmup builds trust in your inbox. It can't make people want an email they didn't expect.

Before you hit send

  • One DMARC record at _dmarc.yourcompany.com, set to p=none, with a reports address you check.
  • A test email from your mail merge tool shows dmarc=pass under Show original.
  • Every service that sends email as your domain passes SPF or DKIM.
  • Everyone on your list expects to hear from you, and can easily opt out.

Not sure about your setup? Our free checker gives you a plain-English answer.

Check your domain for free

Frequently asked questions

Gmail only requires DMARC from senders of more than 5,000 messages a day to Gmail accounts, but Google recommends SPF, DKIM and DMARC for every domain. Yahoo also urges every sender to publish a DMARC policy. A p=none record takes ten minutes and doesn’t change how your email is delivered, so there’s little reason to wait.

No. Google says that under p=none your messages are delivered normally, with no risk of being rejected or sent to spam because of DMARC. The DMARC standard says a none policy must not change how receivers handle your mail. You just start getting reports.

No. Google says you don’t need to do anything in the Admin console for DMARC. You publish the record at your domain host, the company where you manage your domain’s settings, and that’s the only place it needs to go.

Yes, but the other domain has to agree to receive them. Google says to add a TXT record at the other domain with the host name yourcompany.com._report._dmarc.[the other domain] and the value v=DMARC1;. Without it, receivers won’t send reports there. Using an address on your own domain avoids this step.

Not usually. Subdomains follow the policy on your main domain’s record unless you add an sp tag to set a different policy for them. A separate domain is different: yourcompany.co or a second brand domain needs its own DMARC record.

It means Gmail refused your email because it failed DMARC and your domain’s policy asked for that. Check that SPF and DKIM pass for the service that sent it, and that they pass for the same domain as your From address. Google lists this error on its DMARC troubleshooting page.

Sources (10)

Check your SPF, DKIM and DMARC for free.

Our free checker reads your domain's public records and explains each result in plain English, with the exact text to paste.

We're launching soon

Get on the waitlist for an exclusive launch discount.

We'll only email you about the launch.