← All installation guides Email authentication and DNS

Set up Google Workspace DKIM for an Email Sender Seal

Generate a Google Workspace DKIM key, publish it in DNS, start authentication and identify the selector.

GW✉
Recommended methodEmail DNS and seal setup
Email authentication setup

Configure email DNS and find the selector

  1. 1

    Open Authenticate email

    As a Google Workspace administrator open Apps, Google Workspace, Gmail and Authenticate email, then select the sender domain.

  2. 2

    Generate the record

    Choose Generate New Record, select the supported key length and choose a prefix selector. Google recommends google unless that selector is already in use.

  3. 3

    Publish the TXT record

    Copy the DNS host name and TXT value exactly into the authoritative DNS provider. Wait for DNS propagation before returning to Google.

  4. 4

    Start authentication

    Return to Authenticate email, select the domain and choose Start authentication. Send a new message to an external mailbox and confirm Authentication-Results reports DKIM pass.

  5. 5

    Enter the selector in VerifySeal

    Use the prefix selected in Google Admin or confirm the s= value in Show original. Enter only that selector, then run the VerifySeal email DNS check.

Open Google Workspace DKIM documentation ↗
Email Sender Verification Seal

Complete authentication before installing the seal

The sender domain must continue to publish a valid SPF record, the selected DKIM key and a DMARC policy. VerifySeal automatically rechecks these records according to the administrator schedule. For High Security messages, DKIM must cover the final Message-ID, VEM header and completed body.

  • SPF authorizes sending services
  • DKIM verifies the signed message domain
  • DMARC publishes the domain policy
Testing checklist

Confirm the installation is working

01

SPF

The sender domain has one valid SPF record containing every authorized sending service.

02

DKIM

A new external message reports DKIM pass and its matching signature contains the selector entered in VerifySeal.

03

DMARC

A DMARC record is published at _dmarc and its policy matches the organization’s approved rollout.

04

VerifySeal

The customer order reports SPF, DKIM and DMARC as verified before the Email Sender Seal is issued.

Platform notes
  • Each sending domain needs its own DKIM setup. Google advises that new Gmail activations can take time before a DKIM key can be generated.