Fix library / dkim-not-aligned-google-workspace
Why Gmail says your DKIM isn't aligned (Google Workspace fix)
WHAT YOU'RE SEEING
A DMARC check shows DKIM authenticated but not aligned. The signing domain looks like "abc123.gappssmtp.com".
WHY IT'S HAPPENING
Google Workspace defaults to signing your mail with its own "gappssmtp.com" subdomain — not your actual domain. DKIM technically passes, but it doesn't align with your From address, so DMARC fails.
How to fix it
- 1
Open Google Admin Console (admin.google.com).
- 2
Go to Apps → Google Workspace → Gmail → Authenticate email.
- 3
Select your domain.
- 4
Click "Generate new record".
- 5
Copy the displayed TXT record into your DNS at the specified host (usually google._domainkey.yourdomain.com).
- 6
Wait 30 minutes for DNS to propagate.
- 7
Back in Admin, click "Start authentication".
Provider-specific instructions
Microsoft 365
- 1.Open Microsoft Defender portal → Email & collaboration → Policies & rules → Threat policies → DKIM.
- 2.Select your domain and click "Enable".
- 3.Add the two CNAME records shown to your DNS.
Where do I add these records? (by DNS host)
Records go in the DNS panel of whoever hosts your domain, not inside Gmail or Outlook. Find your host below.
Cloudflare
- 1.Log in and pick your domain.
- 2.Open the DNS tab, then Records.
- 3.Click Add record, choose the type (TXT/CNAME), paste the Name and Value, Save.
- 4.Tip: Conductor can apply Cloudflare records for you. Connect a token on your domain page instead of doing this by hand.
GoDaddy
- 1.Go to My Products, find your domain, click DNS.
- 2.Under Records, click Add.
- 3.Pick the type, enter the Name (Host) and Value, Save. Use "@" for the root domain.
Crazy Domains
- 1.Log in, go to My Account, then Manage next to your domain.
- 2.Open DNS / Manage DNS.
- 3.Add a record, choose the type, enter the Hostname and Value, Save.
VentraIP
- 1.Log in to VIPControl, open Domain Names, click your domain.
- 2.Choose Manage DNS / DNS Zone.
- 3.Add a record with the type, name and content shown above, Save.
Squarespace / Google Domains
- 1.Open Settings, then Domains, and pick your domain.
- 2.Choose DNS Settings, scroll to Custom Records.
- 3.Add the record type, host and data, Save.
Namecheap
- 1.Go to Domain List, click Manage next to your domain.
- 2.Open the Advanced DNS tab.
- 3.Click Add New Record, set the type, host and value, and save with the green tick.
Not listed? The steps are the same everywhere: find DNS or Manage DNS, add a record, pick the type, paste the name and value shown above.
Not sure if this is your problem?