Updated: 28 September 2026 · Applies to: Google Workspace (Google Admin console)
DMARC tells other mail servers what to do with mail that claims to come from your domain but fails the SPF and DKIM checks, and it sends you reports about who is sending mail in your name. It protects your domain against forgery. You publish it as a TXT record in DNS.
Before you start
- SPF and DKIM must be set up: How to set up an SPF record for Google Workspace? and How to set up DKIM for Google Workspace?. Google says to allow 48 hours after setting them up before you set up DMARC.
- Create a mailbox or a group that receives the DMARC reports, for example
dmarc@example.com. Reports arrive as many small automatic emails, so a group or a dedicated mailbox is better than your own inbox.
Add the DMARC record
- Type: TXT
- Name / Host:
_dmarc(some panels need the full name_dmarc.example.com.) - Value:
v=DMARC1; p=none; rua=mailto:dmarc@example.com
- Add the record at your DNS host. For Ucartz cPanel hosting see How to add Google Workspace DNS records (MX, SPF, DKIM, DMARC) in cPanel?.
- Check it:
dig +short TXT _dmarc.example.commust return your value.
Roll it out in steps
Google recommends to start with the policy p=none, which only collects reports and does not block anything. Read the reports for a few weeks to find every system that sends mail for your domain (your website, a newsletter service, a helpdesk) and make sure each one passes SPF or DKIM. Then tighten the policy over time:
p=none: monitoring only.p=quarantine: failing mail goes to the spam folder.p=reject: failing mail is refused.
Google's own example of a strict record is v=DMARC1; p=reject; rua=mailto:postmaster@example.com, mailto:dmarc@example.com; pct=100; adkim=s; aspf=s. Use such a strict setting only after your reports show that all your legitimate mail passes.
Common mistakes
- Going to
rejecttoo early. Legitimate mail from a forgotten system (for example a website form) is then refused. - Two DMARC records. A domain must have exactly one record at
_dmarc. - The report address is at another domain without permission. Use an address in your own domain.
- Missing SPF or DKIM. DMARC needs at least one of them to pass and to match the domain in the From address.
Frequently asked questions
Do I have to read the reports myself?
The reports are XML files. Many free and paid services turn them into readable dashboards; point rua to the address such a service gives you.
Does DMARC affect mail I receive?
No. It only concerns mail sent from your domain, and how other servers treat it.
Official documentation: Google Workspace Admin help: set up DMARC.
Need Google Workspace or help with the DNS records?
- Google Workspace: plans for your business email, calendar, Drive and Meet, available in the Ucartz store.
Prefer a hand with the setup? Our engineers can do it for you: Hire an Expert, or use our on-demand server management.
