If you use Google Workspace (Gmail) for your domain email, we recommend configuring SPF, DKIM, and DMARC to improve email authentication, deliverability, and protection against email spoofing.
Before You Begin
Before making any DNS changes, we recommend making a copy of your existing DNS records.
If your DNS is managed by Rebel, you can update your records in Advanced DNS.
If your DNS is hosted with another provider, update your DNS records through that provider instead.
Step 1 – Configure SPF
Google recommends publishing the following SPF record:
| Type | Host | Value |
|---|---|---|
| TXT | @ | v=spf1 include:_spf.google.com ~all |
Note: If your domain already has an SPF record, do not create a second SPF record. Update your existing SPF record to include Google's mail servers instead.
Step 2 – Configure DKIM
Unlike SPF, Google Workspace generates a unique DKIM record for every organization.
To configure DKIM:
- Sign in to the Google Workspace Admin Console.
- Generate your DKIM key.
- Copy the DNS record generated by Google.
- Add the DKIM record to your DNS.
- Return to Google Workspace and enable DKIM.
Because each organization has a unique DKIM selector and public key, Rebel cannot provide these values.
Refer to Google's official documentation for the latest instructions.
Step 3 – Configure DMARC
After SPF and DKIM have been configured, Google recommends adding a DMARC record.
A basic DMARC policy is:
| Type | Host | Value |
|---|---|---|
| TXT | _dmarc | v=DMARC1; p=none; |
As you monitor your email authentication results, you may choose to update your DMARC policy to a stricter setting.
Comments
0 comments
Article is closed for comments.