Updated: 28 September 2026 · Applies to: Google Workspace (Google Admin console)
DKIM adds a digital signature to every message you send, so receiving servers can check that the mail really comes from your domain and was not changed on the way. Google creates the key; you publish its public part as a TXT record in DNS and then switch signing on. You need to be a Google Workspace administrator.
Steps
- Sign in to the Google Admin console at admin.google.com with your administrator account.
- Open Menu › Apps › Google Workspace › Gmail, then Authenticate email.
- Select your domain and click Generate New Record.
- Choose the key length: 2048 if your DNS host supports it, otherwise 1024. Keep the default selector prefix
google, which Google recommends for Workspace. - Copy the two values Google shows: the host name of the TXT record, which is
google._domainkeyfor the default selector, and the TXT record value, a long text that starts withv=DKIM1. - Add a TXT record with these two values at your DNS host. For Ucartz cPanel hosting see How to add Google Workspace DNS records (MX, SPF, DKIM, DMARC) in cPanel?. Paste the value as one line. Do not click Start authentication yet: the record must exist in DNS first.
- Wait for the DNS to update. Google says it can take up to 48 hours before DKIM works. Check it with
dig +short TXT google._domainkey.example.com: it must return the long value. - Go back to Menu › Apps › Google Workspace › Gmail › Authenticate email, select the domain and click Start authentication.
The status of the domain then shows that DKIM authentication is on. If Google reports that it cannot find the record, wait a while and try again.
Check that it works
- Send a mail from a Workspace address to a personal address at another provider.
- Open the message source ("Show original" in Gmail) and look for
DKIM: PASSwith your domain.
Common problems
- The DNS panel adds the domain twice (
google._domainkey.example.com.example.com). Some panels want onlygoogle._domainkey, others the full name. Look at how existing records in your panel are written, and check the result withdig. - The value is rejected or cut off. Long TXT values may be limited by some DNS hosts. Generate a 1024-bit key instead.
- Extra spaces or quotes in the pasted value. It must be exactly what Google shows, as a single line.
- Start authentication is greyed out or fails. The record is not visible yet, or the selector name differs. Use the selector shown by Google.
Next
Set up DMARC once SPF and DKIM both pass: How to set up DMARC for Google Workspace?. SPF is described in How to set up an SPF record for Google Workspace?.
Frequently asked questions
Do I need a new key for each domain?
Yes. Each domain and domain alias in Workspace gets its own key and record.
Can I use DKIM from another mail service as well?
Yes. Every service uses its own selector name, so several DKIM records can exist next to each other.
Official documentation: Google Workspace Admin help: set up DKIM.
Need Google Workspace or help with the DNS records?
- Google Workspace: plans for your business email, calendar, Drive and Meet, available in the Ucartz store.
Prefer a hand with the setup? Our engineers can do it for you: Hire an Expert, or use our on-demand server management.
