How do I set up DMARC for Google Workspace?

DMARC is a TXT record named _dmarc in your domain's DNS settings, not a switch in the Google Admin console. Set up SPF and DKIM first, then add a DMARC record with p=none and an inbox you read. Once your real email keeps arriving normally, change it to p=quarantine and keep a dated check result.
DMARC is a record on your email domain that tells other mail servers what to do with fake email pretending to be from you. It works with two other records, SPF and DKIM, so you set up all three.
Check if you already have it
Run the free email check on HowyGuard with your business domain. It shows whether SPF, DKIM and DMARC are each set up. If all three pass and DMARC says p=quarantine or p=reject, you're done.
How to set it up
Before you start, you need your Google Workspace admin sign-in and a sign-in for wherever your domain's DNS lives, usually the company you bought the domain from. Also list anything else that sends email as you, like booking reminders, newsletters or your website's contact form. Search each one's help pages for "SPF" and "DKIM" and add what they give you, or their mail may go to junk later.
Set up SPF, DKIM and DMARC for Google Workspace
Google Workspace, needs your Google Workspace admin sign-in and your domain's DNS settings
- Sign in where your domain's DNS settings live. That's usually where you bought the domain, like GoDaddy, Namecheap, Squarespace or Wix. Look for DNS or Manage DNS.
- SPF: add a TXT record with the name
@and this value. If a booking tool also sends email as you, add its include before~all. Keep one SPF record only.v=spf1 include:_spf.google.com ~all - DKIM: sign in at
admin.google.com, go to Apps, then Google Workspace, then Gmail, then Authenticate email. Pick your domain, click Generate new record, and add the TXT record Google shows to your DNS. Once the record is live, click Start authentication. - Google asks you to "Allow 48 hours after setting up SPF and/or DKIM before setting up DMARC." Wait that long after the DKIM step before you add the DMARC record.
- DMARC: add a TXT record with the name
_dmarcand this value, using an inbox you read:v=DMARC1; p=none; rua=mailto:you@yourbusiness.ca - Leave it on
p=noneat first. Once the DMARC reports show your real email arriving normally, changep=nonetop=quarantine. That's the step that sends fakes to junk.
How to show it's true: Run the free email check on howyguard.com and screenshot the result showing all three passing.
- You already have an SPF record: edit it instead of adding a second one.
How to show it's done
Run the free email check again and keep a dated screenshot showing all three passing. Note the date you changed to p=quarantine. File both in your proof folder.
Common questions
What do p=none and p=quarantine mean?
p=none means "report only, deliver everything". p=quarantine sends email that fails the checks to junk. p=reject refuses it outright.
My booking reminders started going to junk. What happened?
That service isn't in your SPF or DKIM yet. Add the record it gives in its help pages, or set DMARC back to p=none while you fix it.
I already have an SPF record. Do I add another?
No. Edit the one you have. A domain should have only one.
I use a personal Gmail address. Can I set this up?
No. The gmail.com domain belongs to Google. You need a business address on your own domain first.
Sources
- Google Workspace Admin Help: Set up DMARCsupport.google.com
- Google Workspace Admin Help: Set up SPFsupport.google.com
- Google Workspace Admin Help: Set up DKIMsupport.google.com