This process generates the DKIM record that will be added to your domain’s DNS to authenticate emails sent from Google Workspace.
Step 1: Sign in to Google Admin
Open your web browser and go to:
Log in with your Google Workspace administrator account (not a regular Gmail account).
Note: If you’re not sure which account is the administrator, it’s usually the account that was used to set up Google Workspace.
Step 2: Open Gmail Settings
On the Admin Home page:
- Click Apps
- Click Google Workspace
- Click Gmail
Step 3: Open Email Authentication
Scroll down and click:
Authenticate Email (DKIM)
(Sometimes it is listed under “Authenticate email” depending on the version of Google Admin.)
Step 4: Select Your Domain
If you have more than one domain, choose the one you are sending emails from.
Step 5: Generate a DKIM Key
If DKIM has never been set up before, you’ll see a button that says:
Generate New Record
Click it.
Use these settings:
- Key Length: 2048-bit (recommended)
- Selector Prefix: Leave the default (google) unless instructed otherwise.
Click:
Generate
Step 6: Copy the DNS Record
Google will display something similar to:
Host Name
google._domainkey
TXT Value
v=DKIM1; k=rsa; p=MIIBIjANBgkqh…
Stop here.
Do not click Start Authentication yet.
What to Do Next
Once you have generated the DKIM record:
- Do not click “Start Authentication” yet.
- Copy the entire DKIM record (or take a screenshot of the page).
- Send it to us.
We will:
- Add the DKIM record to your DNS.
- Verify that the DNS record has propagated.
- Notify you when it’s ready.
- Ask you to return to Google Admin and click Start Authentication to complete the setup.
Once authentication has started, Google Workspace will begin digitally signing outgoing email from your domain using DKIM.
Step 7: Verify Authentication
After DNS has updated:
Return to:
Apps → Google Workspace → Gmail → Authenticate Email (DKIM)
Click:
Start Authentication
If successful, you’ll see a status indicating DKIM is enabled for your domain.
