
Namecheap + Google Workspace: SPF, DKIM and DMARC setup that passes
Every record in the exact fields Namecheap asks for, the Google Workspace side done properly, and the mistakes that break mail for people doing it alone.
Free guides · no signup
Most guides tell you what a TXT record is. These tell you exactly where to click in your registrar's DNS panel, what to paste, and which mistake breaks mail for half the people who try it alone. Twenty-eight combinations, written and kept current by a developer who fixes email authentication every week.
Start here

Every record in the exact fields Namecheap asks for, the Google Workspace side done properly, and the mistakes that break mail for people doing it alone.
The full matrix
All twenty-eight are published. Each carries its registrar's actual DNS panel path and field names, and its provider's real SPF include, DKIM selector type and activation step — not one article with the names swapped.
| Registrar / DNS host | Google Workspace | Microsoft 365 | Zoho Mail | Titan / cPanel Mail |
|---|---|---|---|---|
| Namecheap | Read guide → | Read guide → | Read guide → | Read guide → |
| GoDaddy | Read guide → | Read guide → | Read guide → | Read guide → |
| Hostinger | Read guide → | Read guide → | Read guide → | Read guide → |
| Cloudflare | Read guide → | Read guide → | Read guide → | Read guide → |
| Bluehost | Read guide → | Read guide → | Read guide → | Read guide → |
| SiteGround | Read guide → | Read guide → | Read guide → | Read guide → |
| HostGator | Read guide → | Read guide → | Read guide → | Read guide → |
Need a combination that is not listed — a self-hosted mail server, a marketing platform like Mailchimp or Klaviyo alongside your mailbox? Ask us; those are the ones people get wrong most often.
Free tool
Type a domain and read the actual published records, with the common faults flagged —
duplicate SPF, missing DMARC, a policy still set to p=none.
No signup, no email required, nothing stored.
Before you start
Worth reading before you open your DNS panel — the second one is the mistake that causes most of the damage.
Yes. SPF lists which servers may send mail for your domain, DKIM cryptographically signs each message so it cannot be altered in transit, and DMARC tells the receiving server what to do when a message fails either check. Gmail and Microsoft now expect all three from anyone sending at volume, and a missing DMARC record alone is enough to put legitimate mail in the spam folder.
No — and this is the mistake that breaks the most mail. A domain may have exactly one SPF TXT record. Adding a second one when you connect a new mail provider makes SPF fail entirely, which is worse than having none at all. The correct move is to merge the new provider’s include into your existing record.
Usually 15 to 60 minutes, occasionally up to 48 hours depending on the TTL your registrar has set. Dropping the TTL to 300 seconds a day before you make changes shortens the wait considerably — and gives you a fast rollback if something is wrong.
Free 15-minute consultation
Tell us what you need built or fixed. You get an approach, a timeline and a fixed price — usually within a few hours.
Welcome back! Sign in to your account.
Don't have an account?
Create your Mahatosoft client account.
Already have an account?