In the Google Admin console, go to Apps, then Google Workspace, then Gmail, then Authenticate email, and generate a 2048-bit DKIM key for yourbusiness.com. Add the key as a TXT record at google._domainkey.yourbusiness.com, then come back to the same page and click Start authentication.
What DKIM does for Google Workspace email
DKIM is a digital signature that proves an email came from your domain and wasn't changed on the way. Gmail adds the signature when you send. Receiving mailboxes check it against a public key you publish in your DNS, which is the public address book for your domain.
Without your own key, email from Google Workspace isn't signed for yourbusiness.com. It may still pass SPF, but DKIM is the stronger proof, and it survives forwarding where SPF often fails. Gmail and Yahoo require both SPF and DKIM from bulk senders, and a DMARC record that relies on them.
Before you start
- You must be signed in to the Admin console as a super administrator.
- If you've only just turned on Gmail for your organization, Google says to wait 24 to 72 hours before you can get your DKIM key.
- You need a login for your DNS provider. That is usually where you bought the domain, your website host, or Cloudflare.
Step 1: Generate the key
- Sign in to the Google Admin console at admin.google.com.
- Open the menu and go to Apps, then Google Workspace, then Gmail.
- Click Authenticate email.
- Choose yourbusiness.com from the Selected domain menu.
- Click Generate new record.
- For the DKIM key bit length, choose 2048.
- Leave the prefix selector as google. Google recommends the default.
- Click Generate.
Google now shows two things: a DNS host name, google._domainkey, and a TXT record value that starts with v=DKIM1. Keep this page open.
Step 2: Add the TXT record at your DNS provider
Create a new TXT record:
| Type | Name (Host) | Value |
|---|---|---|
| TXT | google._domainkey.yourbusiness.com | v=DKIM1; k=rsa; p=… (copy the full value from the Admin console) |
Most DNS providers add your domain to the name automatically, so enter just google._domainkey. Copy the value in one go, with nothing added or missing at either end. Then save.
If your DNS provider limits TXT record length
A 2048-bit key is longer than 255 characters. Many DNS providers store a long value without any problem. Some reject it, or quietly cut it short, which breaks the signature.
If yours does, Google gives three options:
- Split the key into parts. Break the value into chunks of under 255 characters, put each chunk inside double quotes, and enter them one after another in the same Value field, for example "v=DKIM1; k=rsa; p=MIIBIj…" "…IDAQAB". Receivers join the parts back together.
- Ask your DNS provider whether it supports TXT records longer than 255 characters.
- Use a 1024-bit key instead. Go back to Step 1 and choose 1024. It works, but it is the weaker option, so only use it if the first two don't.
Step 3: Click Start authentication
Wait for the record to appear in DNS. That can be minutes, but Google says DKIM can take up to 48 hours to start working.
Then go back to Apps, Google Workspace, Gmail, Authenticate email, choose yourbusiness.com and click Start authentication. When everything is working, the status at the top of the page changes to Authenticating email with DKIM.
If the status doesn't change, compare the TXT record with the value in the Admin console, give DNS more time, and click Start authentication again.
How to check DKIM is working
There are three ways, from quickest to most complete.
- Look up the record. Google's Admin Toolbox Dig tool shows what your DNS is publishing. Look up the TXT record for google._domainkey.yourbusiness.com and compare it with the Admin console. A key split into two parts is normal.
- Check a real message. Send an email from your Google Workspace account to a personal Gmail address. Open it, choose Show original from the three-dot menu, and check that DKIM shows PASS for yourbusiness.com.
- Run a full test. Send one email to your private test address. The report shows whether DKIM passes for your own domain, whether SPF and DMARC pass and align, and a verdict for Gmail, Google Workspace, Outlook.com, Microsoft 365 and Yahoo, with the exact fix for anything missing.
Common problems
- The value was cut short. The key looks complete in your DNS screen but fails the check. Split it into quoted parts as described above, or ask your DNS provider.
- The name is doubled. You typed the full name and your provider added the domain again, giving google._domainkey.yourbusiness.com.yourbusiness.com. Change the name to google._domainkey.
- You have more than one domain. Each domain in Google Workspace needs its own key. Pick each one from the Selected domain menu and repeat the steps.
- Other services still fail DKIM. This key only signs email sent through Gmail. Mailchimp, HubSpot, Shopify and other services that send as your domain need their own DKIM setup.
What to do next
Once DKIM passes, add a DMARC record if you don't have one. Google recommends waiting at least 48 hours after setting up SPF and DKIM before you do. Start with monitoring mode:
| Type | Name (Host) | Value |
|---|---|---|
| TXT | _dmarc.yourbusiness.com | v=DMARC1; p=none; rua=mailto:dmarc-reports@yourbusiness.com |
Change the rua address to a mailbox you read. Once reports show all your genuine email passing, move to p=quarantine.
Checked against: Google Workspace Admin Help, Set up DKIM · Google Workspace Admin Help, Troubleshoot DKIM issues · Google Workspace Admin Help, Email sender guidelines.