/DOCSMANAGEFIX_EMAIL_DELIVERABILITY
MANAGE

Fix Email Deliverability

Set up SPF, DKIM, and DMARC so your Google Workspace emails land in inboxes instead of spam.

Fix Email Deliverability

Emails sent from your Google Workspace domain — especially from secondary or alias domains — can land in spam when authentication records are missing, domain alignment is poor, or the sender reputation is low.

This guide walks through the three core fixes: SPF, DKIM, and DMARC. Each domain is evaluated independently, so every domain that sends mail needs its own records.

Step 1 — Add an SPF record

SPF tells receiving servers which IP addresses are allowed to send mail for your domain.

  1. Open your DNS provider (Cloudflare, GoDaddy, Namecheap, etc.).

  2. Add a TXT record at the root (@) of the domain with this value:

    v=spf1 include:_spf.google.com ~all
    
  3. Save and wait for propagation (usually a few minutes).

One SPF record per domain. If you already have an SPF record, merge the include:_spf.google.com part into the existing record instead of adding a second TXT record.

Step 2 — Set up DKIM

DKIM adds a cryptographic signature to outgoing mail so receivers can verify it was not altered in transit.

  1. Sign in to admin.google.com as a super-admin.
  2. Go to Apps → Google Workspace → Gmail.
  3. Click Authenticate email (DKIM).
  4. Select the domain you want to secure and click Generate new record.
  5. Copy the TXT record name and value Google provides.
  6. Add that TXT record to your DNS provider.
  7. Return to Google Admin and click Start authentication.

Generate DKIM for every domain that sends mail. Secondary and alias domains each need their own key.

Step 3 — Add a DMARC record

DMARC tells receivers what to do when SPF or DKIM fails, and where to send aggregate reports.

  1. In your DNS provider, add a TXT record at _dmarc with a monitoring policy:

    v=DMARC1; p=none; rua=mailto:your@email.com;
    
  2. After you confirm legitimate mail is passing, tighten the policy:

    • p=quarantine — treat failures as suspicious.
    • p=reject — block failed mail outright.

Start with p=none. A strict policy applied too early can cause legitimate mail to be rejected while you are still fixing alignment issues.

Step 4 — Verify domain alignment

Even with SPF, DKIM, and DMARC in place, mail can still fail authentication if the domains do not align:

  • The "From" address should match the sending domain.
  • The DKIM signing domain should align with the "From" domain.
  • Avoid sending from noreply@one-domain.com while the envelope sender is mail@another-domain.com.

Google and most major providers treat misaligned domains as suspicious.

Step 5 — Warm up the domain and improve sender reputation

New domains or domains with low sending history need time to build trust:

  • Start small — send low volumes at first.
  • Target engaged recipients — people who open and reply help establish positive signals.
  • Gradually increase volume — ramp up over days or weeks, not hours.
  • Avoid spam triggers — keep subject lines clear, avoid excessive punctuation or all-caps words, and use a recognizable sender name.
  • Set a valid reply-to address and encourage replies when appropriate.

Step 6 — Test and monitor

Before sending campaigns or critical mail, confirm everything passes:

  1. Send a message from the domain to a personal Gmail account.
  2. In Gmail, open the message, click the More menu (⋮), and choose Show original.
  3. Look for SPF, DKIM, and DMARC results. All three should say PASS.

Monitoring tools

  • Google Postmaster Tools — track domain reputation, spam rate, and authentication results for Gmail receivers.
  • MXToolbox — check if your domain or IP is on any blacklists.

How long until things improve?

DNS propagation and reputation updates are not instant. Most senders see better inbox placement within a few days of fixing SPF, DKIM, and DMARC. Domains with a poor reputation history may take one to two weeks.

Need help?

If authentication keeps failing after you have added the records, open a support ticket from the Support entry on the Mercurie dashboard. Include a screenshot of your DNS records and the Gmail "Show original" results so we can spot alignment or syntax issues quickly.

Login to your Mercurie Account