Fix Email Deliverability
Emails sent from your Google Workspace domain — especially from secondary or alias domains — can land in spam when authentication records are missing, domain alignment is poor, or the sender reputation is low.
This guide walks through the three core fixes: SPF, DKIM, and DMARC. Each domain is evaluated independently, so every domain that sends mail needs its own records.
Step 1 — Add an SPF record
SPF tells receiving servers which IP addresses are allowed to send mail for your domain.
-
Open your DNS provider (Cloudflare, GoDaddy, Namecheap, etc.).
-
Add a TXT record at the root (
@) of the domain with this value:v=spf1 include:_spf.google.com ~all -
Save and wait for propagation (usually a few minutes).
One SPF record per domain. If you already have an SPF record, merge the
include:_spf.google.compart into the existing record instead of adding a second TXT record.
Step 2 — Set up DKIM
DKIM adds a cryptographic signature to outgoing mail so receivers can verify it was not altered in transit.
- Sign in to admin.google.com as a super-admin.
- Go to Apps → Google Workspace → Gmail.
- Click Authenticate email (DKIM).
- Select the domain you want to secure and click Generate new record.
- Copy the TXT record name and value Google provides.
- Add that TXT record to your DNS provider.
- Return to Google Admin and click Start authentication.
Generate DKIM for every domain that sends mail. Secondary and alias domains each need their own key.
Step 3 — Add a DMARC record
DMARC tells receivers what to do when SPF or DKIM fails, and where to send aggregate reports.
-
In your DNS provider, add a TXT record at
_dmarcwith a monitoring policy:v=DMARC1; p=none; rua=mailto:your@email.com; -
After you confirm legitimate mail is passing, tighten the policy:
p=quarantine— treat failures as suspicious.p=reject— block failed mail outright.
Start with
p=none. A strict policy applied too early can cause legitimate mail to be rejected while you are still fixing alignment issues.
Step 4 — Verify domain alignment
Even with SPF, DKIM, and DMARC in place, mail can still fail authentication if the domains do not align:
- The "From" address should match the sending domain.
- The DKIM signing domain should align with the "From" domain.
- Avoid sending from
noreply@one-domain.comwhile the envelope sender ismail@another-domain.com.
Google and most major providers treat misaligned domains as suspicious.
Step 5 — Warm up the domain and improve sender reputation
New domains or domains with low sending history need time to build trust:
- Start small — send low volumes at first.
- Target engaged recipients — people who open and reply help establish positive signals.
- Gradually increase volume — ramp up over days or weeks, not hours.
- Avoid spam triggers — keep subject lines clear, avoid excessive punctuation or all-caps words, and use a recognizable sender name.
- Set a valid reply-to address and encourage replies when appropriate.
Step 6 — Test and monitor
Before sending campaigns or critical mail, confirm everything passes:
- Send a message from the domain to a personal Gmail account.
- In Gmail, open the message, click the More menu (⋮), and choose Show original.
- Look for SPF, DKIM, and DMARC results. All three should say PASS.
Monitoring tools
- Google Postmaster Tools — track domain reputation, spam rate, and authentication results for Gmail receivers.
- MXToolbox — check if your domain or IP is on any blacklists.
How long until things improve?
DNS propagation and reputation updates are not instant. Most senders see better inbox placement within a few days of fixing SPF, DKIM, and DMARC. Domains with a poor reputation history may take one to two weeks.
Need help?
If authentication keeps failing after you have added the records, open a support ticket from the Support entry on the Mercurie dashboard. Include a screenshot of your DNS records and the Gmail "Show original" results so we can spot alignment or syntax issues quickly.