Fix guides › Google Workspace + Cloudflare
Set up SPF, DKIM and DMARC for Google Workspace with Cloudflare DNS
About 20 minutes, plus waiting time. You’ll add four kinds of record so inboxes trust your email and no one else can send email in your name.
Last reviewed 7 October 2026
Before you start, run the email health check on your domain so you can see what’s already in place. Menu names at Google Workspace and Cloudflare change from time to time; if a step looks different, look for the nearest equivalent.
1. Open your DNS records at Cloudflare
Sign in to the Cloudflare dashboard, select your domain, then go to DNS › Records. You’ll see your records and an Add record button.
Select Add record, choose the type, and fill in the Name and content. Cloudflare adds your domain to the name automatically, so type only the part shown below. Leave TTL on Auto.
2. Mail servers (MX)
Google Workspace uses a single MX record: smtp.google.com with priority 1. Add it with Name @ and delete any MX records from a previous provider. (Older setups with five aspmx records still work; you don’t need to change them.)
3. Approved senders (SPF)
Add one TXT record:
| Type | Name | Value |
|---|---|---|
| TXT | @ | v=spf1 include:_spf.google.com ~all |
If a TXT record starting with v=spf1 already exists (Cloudflare Email Routing adds one), select Edit and merge your entries into it instead of adding a second record. Your domain must have exactly one SPF record. If other services send email on your behalf (newsletters, invoicing, a help desk), add their include: to the same record. The SPF record builder does this for you and checks the 10-lookup limit.
4. Email signing (DKIM)
- In the Google Admin console, go to Menu › Apps › Google Workspace › Gmail › Authenticate email.
- Select your domain and choose Generate new record. Pick a 2048-bit key and keep the prefix selector as
google. (If Gmail was switched on in the last day or two, Google may not let you generate a key yet. Try again later.) - Google shows a TXT record name (
google._domainkey) and a long value startingv=DKIM1. Add it as a TXT record at Cloudflare, pasting the whole value in one go. - Return to the Admin console and select Start authentication. It can take up to 48 hours to show as active.
Our DKIM checker looks for the google selector automatically. Run the DKIM checker to confirm the key is published.
5. Spoofing protection (DMARC)
Start in monitor-only mode so nothing breaks while you check that all your real email passes:
| Type | Name | Value |
|---|---|---|
| TXT | _dmarc | v=DMARC1; p=none; rua=mailto:dmarc-reports@yourdomain.com |
Replace the address with a mailbox you control. After two to four weeks, once reports show your own email passing, move to p=quarantine and then p=reject. Our guide to moving DMARC from none to reject walks through it, and the DMARC record builder writes each step’s record.
6. Check your work
DNS changes usually appear within minutes but can take a few hours. Run the email health check again. You’re aiming for a pass on mail servers, SPF and DKIM, with DMARC showing “monitor only” for now.