Configure the sending domain

  • Publish the current Google Workspace SPF guidance where applicable.
  • Enable DKIM signing for each active sending domain in the Admin console.
  • Wait for authentication DNS changes to propagate before judging report results.

Check reports

Google infrastructure can appear under many source IPs. Identify it by the authentication results and known provider ranges rather than relying on a single address.

  • A passing, aligned DKIM signature for your domain is the strongest expected signal.
  • Forwarding can break SPF while DKIM remains valid.
  • Other Google products and third-party relays may need separate configuration.

Roll out deliberately

Google recommends beginning with monitoring, reviewing reports, then moving gradually to quarantine or reject after legitimate traffic is accounted for.

Further readingGoogle Workspace recommended DMARC rollout