If your business uses Google Workspace (business Gmail), here is how to enable the three anti-spoofing protections.
Add a TXT record on your domain:
v=spf1 include:_spf.google.com ~all
For stricter protection, switch to -all once all your sending services are listed.
In the Google Admin console (admin.google.com) → Apps → Google Workspace → Gmail → Authenticate email. Click "Generate new record", add the provided TXT on google._domainkey to your DNS, then click "Start authentication".
Add a TXT on _dmarc.yourdomain.com, starting gently:
v=DMARC1; p=none; rua=mailto:dmarc@yourdomain.com
Monitor, then move to p=quarantine and finally p=reject.
google. You can customize it, and many test tools only look for common names — hence meaningless “DKIM not detected” results. Our report accepts a hand-typed selector to settle the question.~all in place. Google suggests starting soft; once your sending services are listed, move to -all. A permissive SPF weakens everything else.Allow minutes to hours for DNS propagation, then run our free report: it reads your public records and tells you which DKIM selector is actually published. For proof on the receiving side, email yourself and paste the header into our header analyzer. Finally, turn on free monitoring so you are warned if one of those records ever disappears — the kind of regression nobody notices until email starts failing.
Enter your domain: we test your SPF, DKIM, DMARC and website, and give you the exact action plan.
Run the free check