How to set up DKIM in Google Workspace
DKIM signs your outgoing mail with a key whose public half you publish in DNS. In Google Workspace you generate the key in the Admin console, publish it, then switch signing on.
Steps
- In the Admin console go to Apps, then Google Workspace, then Gmail, and open Authenticate email. Gmail must have been on for your organization for 24-72 hours before you can generate a key.
- Pick your domain, select Generate New Record, choose a 2048-bit key if your DNS host allows it (1024 is also offered), keep the default selector
google, and select Generate.
- Copy the two values shown: the DNS host name (TXT record name) and the TXT record value. Add a TXT record in your DNS host using them:
google._domainkey.example.com. TXT "v=DKIM1; k=rsa; p=MIIBIjANBg..."
The p= value is a placeholder; use the exact one Google shows you.
- Wait for DNS to update (Google says up to 48 hours), return to Authenticate email and select Start authentication.
- Send a test to a Gmail address and check the original message for DKIM PASS.
If your DNS host cuts long TXT values, Google's page explains how to split the record; check the source below.
Check your domain
Not sure what your domain publishes today? The checker reads your live DNS and shows what is missing. If you would rather skip the trial and error, the $29 Email Fix Pack gives you ready-to-paste records for your domain; see a sample pack.
Check your domain free
Sources
More email delivery fixes