C
conductor

Fix library / dkim-not-aligned-google-workspace

CRITICALOften searched as: "dkim alignment failed gmail"

Why Gmail says your DKIM isn't aligned (Google Workspace fix)

WHAT YOU'RE SEEING

A DMARC check shows DKIM authenticated but not aligned. The signing domain looks like "abc123.gappssmtp.com".

WHY IT'S HAPPENING

Google Workspace defaults to signing your mail with its own "gappssmtp.com" subdomain — not your actual domain. DKIM technically passes, but it doesn't align with your From address, so DMARC fails.

How to fix it

  1. 1

    Open Google Admin Console (admin.google.com).

  2. 2

    Go to Apps → Google Workspace → Gmail → Authenticate email.

  3. 3

    Select your domain.

  4. 4

    Click "Generate new record".

  5. 5

    Copy the displayed TXT record into your DNS at the specified host (usually google._domainkey.yourdomain.com).

  6. 6

    Wait 30 minutes for DNS to propagate.

  7. 7

    Back in Admin, click "Start authentication".

Provider-specific instructions

Microsoft 365

  1. 1.Open Microsoft Defender portal → Email & collaboration → Policies & rules → Threat policies → DKIM.
  2. 2.Select your domain and click "Enable".
  3. 3.Add the two CNAME records shown to your DNS.
Where do I add these records? (by DNS host)

Records go in the DNS panel of whoever hosts your domain, not inside Gmail or Outlook. Find your host below.

Cloudflare

  1. 1.Log in and pick your domain.
  2. 2.Open the DNS tab, then Records.
  3. 3.Click Add record, choose the type (TXT/CNAME), paste the Name and Value, Save.
  4. 4.Tip: Conductor can apply Cloudflare records for you. Connect a token on your domain page instead of doing this by hand.

GoDaddy

  1. 1.Go to My Products, find your domain, click DNS.
  2. 2.Under Records, click Add.
  3. 3.Pick the type, enter the Name (Host) and Value, Save. Use "@" for the root domain.

Crazy Domains

  1. 1.Log in, go to My Account, then Manage next to your domain.
  2. 2.Open DNS / Manage DNS.
  3. 3.Add a record, choose the type, enter the Hostname and Value, Save.

VentraIP

  1. 1.Log in to VIPControl, open Domain Names, click your domain.
  2. 2.Choose Manage DNS / DNS Zone.
  3. 3.Add a record with the type, name and content shown above, Save.

Squarespace / Google Domains

  1. 1.Open Settings, then Domains, and pick your domain.
  2. 2.Choose DNS Settings, scroll to Custom Records.
  3. 3.Add the record type, host and data, Save.

Namecheap

  1. 1.Go to Domain List, click Manage next to your domain.
  2. 2.Open the Advanced DNS tab.
  3. 3.Click Add New Record, set the type, host and value, and save with the green tick.

Not listed? The steps are the same everywhere: find DNS or Manage DNS, add a record, pick the type, paste the name and value shown above.

Not sure if this is your problem?

Related fixes