Is your Google Workspace domain set up correctly?
Checks your MX, SPF, DKIM, and DMARC records against what Google Workspace actually requires. Free, instant, no email needed.
Checks your MX, SPF, DKIM, and DMARC records against what Google Workspace actually requires. Free, instant, no email needed.
I run into the same four broken records over and over when I diagnose why a Google Workspace domain is landing in spam. Here is what each one actually does, so the results above mean something instead of just being pass or fail.
Your MX records tell the rest of the internet which servers handle incoming mail for your domain. If you're on Google Workspace, they need to point at Google's mail servers, either the current smtp.google.com format or the older aspmx.l.google.com set. If MX is missing entirely, your domain can't receive mail at all. If it points somewhere else, mail sent to you never reaches Google, it goes wherever the stale record says.
SPF is a DNS record that lists which mail servers are authorized to send email using your domain. When Google Workspace sends on your behalf, your SPF record needs to include Google's sending infrastructure, or receiving mail servers have no way to confirm Google was allowed to do that. Two mistakes show up constantly here. The first is no SPF record at all. The second is having two of them, which is actually worse, because a domain can only have one SPF record and receivers ignore both when they find a second. I see this happen when a team adds a new record without checking whether one already exists.
DKIM attaches a cryptographic signature to outgoing mail, generated from a private key and verified against a public key published in your DNS at the google._domainkey selector. If that record is missing, your mail goes out unsigned, and mailbox providers have less confidence the message is genuinely from you and hasn't been altered in transit. Turning DKIM on in Google Workspace involves generating the key in the admin console and publishing the matching TXT record. It's a step people skip because Workspace works fine without it, until reputation and inbox placement start depending on it.
DMARC tells receiving servers what to do when a message claims to be from your domain but fails SPF or DKIM. It has three settings. p=none only monitors and reports, it doesn't stop anything. p=quarantine sends failing mail to spam. p=reject blocks it outright. Google and Yahoo's 2024 bulk sender rules require a published DMARC record for anyone sending more than 5,000 messages a day, and I'd recommend one regardless of volume, since without it there's no real policy in place at all, just a suggestion.
Workspace will let you send mail with none of this configured. That's the trap. Nothing in the product stops you from operating without SPF, DKIM, or DMARC, but Gmail and other mailbox providers use exactly these signals to decide whether your mail is trustworthy enough for the inbox. Passing all four checks doesn't guarantee inbox placement on its own, sender reputation and engagement matter too, but failing any of them is one of the fastest ways to end up in spam regardless of how good your content is.