Email Fix Pack

How to set up DMARC for Google Workspace

Before you start

Google's instructions require SPF and/or DKIM to be set up first, and say to allow 48 hours after setting them up before adding DMARC.

Steps

  1. Create a mailbox or Google Group to receive reports, for example dmarc-reports@example.com. Report volume can be large.
  2. At your domain host's DNS, add a TXT record with host _dmarc (that is, _dmarc.example.com). Start in monitoring mode:
    _dmarc.example.com.  TXT  "v=DMARC1; p=none; rua=mailto:dmarc-reports@example.com"
  3. Allow time for DNS to propagate, then review the daily reports for legitimate senders that fail.
  4. Fix those senders (add to SPF, enable DKIM), then move the policy up, as Google recommends, gradually:
    v=DMARC1; p=quarantine; pct=25; rua=mailto:dmarc-reports@example.com
    v=DMARC1; p=reject; rua=mailto:dmarc-reports@example.com

Policy values

none delivers and logs; quarantine sends failing mail to spam; reject rejects it. Google's own example ends with adkim=s; aspf=s (strict alignment), which is optional and stricter than the default.

Check your domain

Not sure what your domain publishes today? The checker reads your live DNS and shows what is missing. If you would rather skip the trial and error, the $29 Email Fix Pack is the fastest route: ready-to-paste records for your domain.

Check your domain free

Sources

  • Google Workspace Admin Help: Set up DMARC
  • Google: Email sender guidelines

More email delivery fixes

Email Fix Pack

Terms · Privacy · Refunds