Fix guides › Google Workspace + GoDaddy

Set up SPF, DKIM and DMARC for Google Workspace with GoDaddy DNS

About 20 minutes, plus waiting time. You’ll add four kinds of record so inboxes trust your email and no one else can send email in your name.

Last reviewed 7 October 2026

Before you start, run the email health check on your domain so you can see what’s already in place. Menu names at Google Workspace and GoDaddy change from time to time; if a step looks different, look for the nearest equivalent.

1. Open your DNS records at GoDaddy

Sign in to GoDaddy, open My Products (or Domain Portfolio), select your domain and choose DNS. You’ll see a list of your records and an Add New Record button.

Select Add New Record, choose the type, and fill in the Name and Value. GoDaddy adds your domain to the name automatically, so type only the part shown below. Leave TTL at the default (1 hour).

2. Mail servers (MX)

Google Workspace uses a single MX record: smtp.google.com with priority 1. Add it with Name @ and delete any MX records from a previous provider. (Older setups with five aspmx records still work; you don’t need to change them.)

3. Approved senders (SPF)

Add one TXT record:

TypeNameValue
TXT@v=spf1 include:_spf.google.com ~all

If a TXT record starting with v=spf1 already exists, select the pencil icon to edit it instead of adding a new one. Your domain must have exactly one SPF record. If other services send email on your behalf (newsletters, invoicing, a help desk), add their include: to the same record. The SPF record builder does this for you and checks the 10-lookup limit.

4. Email signing (DKIM)

  1. In the Google Admin console, go to Menu › Apps › Google Workspace › Gmail › Authenticate email.
  2. Select your domain and choose Generate new record. Pick a 2048-bit key and keep the prefix selector as google. (If Gmail was switched on in the last day or two, Google may not let you generate a key yet. Try again later.)
  3. Google shows a TXT record name (google._domainkey) and a long value starting v=DKIM1. Add it as a TXT record at GoDaddy, pasting the whole value in one go.
  4. Return to the Admin console and select Start authentication. It can take up to 48 hours to show as active.

Our DKIM checker looks for the google selector automatically. Run the DKIM checker to confirm the key is published.

5. Spoofing protection (DMARC)

Start in monitor-only mode so nothing breaks while you check that all your real email passes:

TypeNameValue
TXT_dmarcv=DMARC1; p=none; rua=mailto:dmarc-reports@yourdomain.com

Replace the address with a mailbox you control. After two to four weeks, once reports show your own email passing, move to p=quarantine and then p=reject. Our guide to moving DMARC from none to reject walks through it, and the DMARC record builder writes each step’s record.

6. Check your work

DNS changes usually appear within minutes but can take a few hours. Run the email health check again. You’re aiming for a pass on mail servers, SPF and DKIM, with DMARC showing “monitor only” for now.