SPF Record for Google Workspace: Copy-Paste Setup Guide
The Warmuply TeamLast checked: October 2026
You're about to send your first mail merge from your Google Workspace address, and someone told you to "set up SPF". This guide gives you the SPF record for Google Workspace to copy, shows where to paste it, and covers a common snag: a domain that already has an SPF record.
It takes about 10 minutes, then up to 48 hours to take effect. You don't need the Google Admin console or any technical background.
What is the SPF record for Google Workspace?
If Google Workspace is the only service that sends email from your domain, copy this:
v=spf1 include:_spf.google.com ~all
That's the record Google gives in its own help pages. What each part means:
| Part | What it does |
|---|---|
v=spf1 | Says "this is an SPF record". It always comes first. |
include:_spf.google.com | Allows Google's mail servers to send for your domain. _spf.google.com is Google's own list of its sending servers. |
~all | Tells receiving servers to treat mail from anyone not on the list as suspicious. It always comes last. |
SPF (Sender Policy Framework) is a line of text on your domain (the part after the @, like yourcompany.com) that lists which services may send email as you. When Gmail or Outlook gets an email from you@yourcompany.com, it checks that list. If the sending server is on it, the email passes SPF.
SPF is one of three settings that prove who you are. The other two are DKIM (a digital signature on each email) and DMARC (rules for what to do when a check fails).
For a plain-English tour of all three, read SPF, DKIM and DMARC explained.
Check whether your domain already has an SPF record
Check first: adding a second SPF record is an easy way to break SPF, and your domain can have only one. If you bought your domain through Google when you signed up for Workspace, it may already be set up.
Run your domain through our free SPF, DKIM and DMARC checker to see what's there now.
You'll get one of three results:
| What you see | What to do |
|---|---|
| No SPF record | Add the Google record using the steps below. |
An SPF record that already includes _spf.google.com | You're set. Skip to "How to check SPF is working". |
An SPF record without _spf.google.com | Don't add a new one. Edit the existing record (see "What to do if an SPF record already exists"). |
How to add the SPF record at your domain host
You add SPF at your domain host: the company that manages your domain's DNS settings, usually where you bought the domain. DNS is the internet's address book for your domain, and SPF lives there as a TXT record, which is simply a record that holds text.
-
Sign in to your domain host. If you're not sure who that is, check where you pay for your domain.
-
Open the DNS settings for
yourcompany.com. Hosts call this page "DNS", "DNS records" or "Manage DNS". -
Add a new record with these values:
Field What to enter Type TXTHost (or Name) @(this meansyourcompany.comitself)Value v=spf1 include:_spf.google.com ~all
- Save the record. Some hosts ask you to wrap the value in quotation marks; your host's help page will say.
- Wait. Google says it can take up to 48 hours for SPF to start working.
Google warns that typos, extra spaces or the wrong quotation marks make the record invalid, so copy and paste rather than type.
If your domain is with GoDaddy, our GoDaddy setup guide for Google Workspace shows where each field is.
What to do if an SPF record already exists
If your domain already has an SPF record, add Google to it. Don't create a second one. With two SPF records, the SPF check fails for every email, and Google warns this can send your mail to spam.
This happens when another service already sends email for your domain, such as a contact form, an online store, a newsletter tool, or the email that came with your web hosting. To merge them:
- Open the existing SPF record. It's the TXT record that starts with
v=spf1. - Keep
v=spf1at the start. - Add
include:_spf.google.comstraight after it. - Keep the other service's
include:if that service still sends email for you. - Keep a single
allat the end. Use~all, which is what Google recommends. - Save, and delete any second SPF record so only one is left.
Merge, don’t add
So if your existing record looks like this:
v=spf1 include:[your other email service] ~all
your merged record looks like this:
v=spf1 include:_spf.google.com include:[your other email service] ~all
Replace [your other email service] with the exact value from your existing record. Don't type the square brackets.
A real example: GoDaddy's email server
Say your domain is with GoDaddy and you see this record:
v=spf1 include:secureserver.net -all
secureserver.net is GoDaddy's email server. GoDaddy's help page says customers using GoDaddy's own email or web hosting need this value.
-
If you still send some email through GoDaddy (its email service, or a website hosted there), keep it and add Google:
v=spf1 include:_spf.google.com include:secureserver.net ~allThis matches the "Google Workspace and GoDaddy" example on Google's own setup page. Note the
-allchanged to~all. -
If you've moved all your email to Google Workspace, remove
include:secureserver.net. Google advises taking out any service that no longer sends email for you. Your record becomesv=spf1 include:_spf.google.com ~all.
Watch the 10-lookup limit
Each include: makes receiving servers look up another list, and SPF allows at most 10 lookups, counting lists inside lists. Go over 10 and SPF fails. Two or three services are nowhere near the limit; for a long record, Google's free Check MX tool (opens in a new tab) counts them. Records also have a 255-character limit.
How to check SPF is working
Wait a few hours, then test with a real email. Two quick ways:
- Run the domain check again. Our checker shows whether your domain has exactly one SPF record and whether it includes Google.
- Read the message details in Gmail. Send an email from
you@yourcompany.comto a personal Gmail address. Open it, click the three-dot More menu next to Reply, then Show original. The summary at the top shows your SPF result. You want it to say PASS.
If it still fails after 48 hours, check the record for typos and make sure there's only one SPF record.
Common SPF mistakes and how to fix them
| Problem | Why it breaks SPF | Fix |
|---|---|---|
Two TXT records starting with v=spf1 | Receiving servers treat SPF as broken | Merge them into one record |
include:_spf.google.com missing | Google isn't on your list | Add it after v=spf1 |
| Typo or extra space | The record can't be read | Paste the value again |
More than one all, or text after all | Anything after all is ignored | Keep a single ~all at the very end |
| An old service still listed | Adds lookups and allows a sender you don't use | Remove its include: |
| Over 10 lookups | SPF fails for every email | Remove unused services |
SPF on yourcompany.com only, but you send from news.yourcompany.com | Each subdomain needs its own record | Add an SPF record for the subdomain |
What SPF does and doesn't do for your mail merge
SPF proves your email really comes from your domain. Gmail requires anyone emailing Gmail addresses to set up SPF or DKIM, and senders of more than 5,000 messages a day need all three.
But passing SPF doesn't decide where your email lands. Inbox providers like Gmail also weigh your sender reputation (your domain's track record), how people react to your email, and what it says.
Spam complaints matter most. When people click "Report spam", your reputation drops fast, even with perfect SPF. Gmail's sender guidelines say to keep your spam rate in Postmaster Tools (Google's free dashboard for senders) below 0.10%, and never let it reach 0.30%.
So once SPF is set up:
- Email people who expect to hear from you, such as customers, candidates who applied, or contacts you've already spoken to.
- Write like a one-to-one email. Keep links to one or two and skip attachments.
- Make it easy to opt out, and stop emailing anyone who asks.
For what else filters look at in the email itself, see our guide to spam trigger words.
SPF also doesn't build trust for a new or quiet inbox. If you haven't sent in bulk from this address before, Warmuply warms it up in the background and shows you a daily safe-send number: how many emails your inbox can safely send today.
Next: DKIM and DMARC
Google recommends setting up all three settings.
Next, follow our guide to turning on DKIM in Google Workspace.
Then add a starter policy with our guide to setting up DMARC for Google Workspace.
Before you hit send
- Your domain has exactly one SPF record, and it includes
include:_spf.google.com.- Any other service that sends email for
yourcompany.comis in that same record, and old ones are removed.- A test email to a personal Gmail address shows SPF as PASS under Show original.
- Everyone on your list expects to hear from you, and your email gives them an easy way to opt out.
Frequently asked questions
No. Gmail’s built-in mail merge sends from your Google Workspace account, and YAMM’s help center says it uses your Gmail account to send. Both go out through Google’s servers, so include:_spf.google.com already covers them. You only add another include for services that send from their own servers.
Google recommends ~all for Google Workspace. With -all, receiving servers may reject email from any sender missing from your record, so one forgotten service can cause bounces or spam-folder problems. Stick with ~all, and use DMARC reports later if you want a fuller picture of who sends for your domain.
Yes. Google’s help says each subdomain you send from needs its own SPF record, and each separate domain needs its own too. A record on yourcompany.com doesn’t cover news.yourcompany.com. If you only send from your main address, one record on the main domain is enough.
Forwarding can break SPF even when your record is correct, because the forwarding server is now the one delivering the message and it isn’t on your list. Google notes this in its SPF troubleshooting page. Setting up DKIM as well gives your email a second way to pass, since Gmail accepts SPF or DKIM.
It depends on your domain host. Google says some hosts need the value wrapped in quotes and others don’t. Check your host’s help page before you save. Either way, the text inside starts with v=spf1 and ends with ~all, with no extra spaces.
Sources (9)
- Set up SPF (checked October 2026)
- About SPF records (checked October 2026)
- Troubleshoot SPF issues (checked October 2026)
- Email sender guidelines (Gmail Help) (checked October 2026)
- Trace an email with its full header (Gmail Help) (checked October 2026)
- Google Admin Toolbox: Check MX (checked October 2026)
- Add an SPF record (GoDaddy Help) (checked October 2026)
- Account, delivery, scheduling (YAMM Documentation) (checked October 2026)
- RFC 7208: Sender Policy Framework (SPF) (checked October 2026)
Related guides
- SPF, DKIM and DMARC Explained in Plain EnglishHere are SPF, DKIM and DMARC explained simply. SPF lists the servers allowed to send email for your domain. DKIM adds a digital signature that…Read the guide
- Check SPF, DKIM and DMARC: Free Plain-English CheckerTo check SPF, DKIM and DMARC, enter your domain in the free checker on this page. It reads your domain’s public DNS records and shows…Read the guide
- Google Workspace SPF on GoDaddy, plus DKIM and DMARCTo set up Google Workspace SPF on GoDaddy, open your domain’s DNS page and add a TXT record with the Name @ and the value…Read the guide
Check your SPF, DKIM and DMARC for free.
Our free checker reads your domain's public records and explains each result in plain English, with the exact text to paste.