Home › Fixes

Google Workspace Emails Going to Spam? Fix Records, Reputation and Volume

By BobWorkUpdated 2026-10-0313 min read
Google Workspace email spam diagnosis with DNS records, reputation and sending volume checks

If Google Workspace emails are going to spam, fix SPF, DKIM and DMARC before you increase sending. Missing or misaligned records make warm-up and campaigns reinforce bad signals instead of repairing them. This guide gives you the exact checks, safe volume ranges, Postmaster Tools signals and proof steps to get delivery back under control.

Start with the admin layer, not the copy. Use the free SPF checker, DKIM checker and DMARC checker while you test. If the mailbox is new, keep the Google-specific setup guide open too: warm up Gmail and Google Workspace.

Why are Google Workspace emails going to spam?

Google Workspace delivery depends on both the domain and the individual user. DNS records authenticate the domain. Each mailbox then builds its own sending pattern through volume, replies, complaints, bounces and consistency.

One broken admin setting can affect every user. One aggressive sender can also damage only their own path. Treat the problem as layered: records first, then reputation, then volume, then content and list quality.

Google’s sender guidance says spam complaint rates should stay below 0.10% and should not reach 0.30% or higher. That margin is small. If your list is weak or your volume jumps suddenly, a few complaints can matter.

The most common causes are predictable:

Do not change five things at once. Fix the first failing layer, send a new test, and record the result.

Which checks prove the cause?

Run one controlled test before changing settings. Send a plain text email from the affected Google Workspace user to a Gmail account you own. In Gmail, open the message, choose More · Show original, and check SPF, DKIM and DMARC.

Then match the result to the likely cause.

SymptomLikely cause5-minute checkFix
SPF fail or softfailSPF missing Google, duplicated, or too complexCheck the root domain TXT recordsPublish one SPF record that includes Google
DKIM missing or failDKIM not enabled in Admin ConsoleAdmin Console · Apps · Google Workspace · Gmail · Authenticate emailGenerate key, publish TXT, start authentication
DMARC missingNo TXT record at _dmarcQuery _dmarc.yourdomain.comAdd DMARC, usually starting with p=none
SPF passes but DMARC failsSender domain is not alignedGmail · Show originalSend from your domain, not a mismatched From domain
New domain lands in spamNo sending reputation yetCheck domain age and previous volumeWarm gradually for 3–4 weeks
Some users failUser-level setup or volume issueCompare headers and sent volumeFix and warm that mailbox separately
Reputation drops after campaignsComplaints, bounces, or sudden volumeGoogle Postmaster ToolsPause, clean the list, reduce volume
Records pass but spam continuesContent, list quality, or domain historyTest plain text to known contactsRemove risky links and verify recipients

A single inbox test does not prove recovery. It only tells you which layer to fix first.

Are SPF, DKIM and DMARC passing?

Authentication is the first repair because it is binary. Either the receiving server can authenticate your mail, or it cannot.

Fix SPF for Google

SPF tells receiving servers which systems may send for your domain. If Google Workspace sends your mail, your root domain needs Google in its SPF record.

The standard Google Workspace SPF record is:

v=spf1 include:_spf.google.com ~all

Add it as a TXT record at your DNS host.

DNS fieldValue
TypeTXT
Host or name@ or blank, depending on DNS host
Valuev=spf1 include:_spf.google.com ~all
TTLDefault is fine

If you also send through SendGrid, Mailgun, Amazon SES, a CRM, or another platform, do not add a second SPF record. Merge every authorised sender into one SPF TXT record.

Common SPF mistakes:

Use Google’s primary setup reference if needed: set up SPF for Google Workspace. After DNS updates, send a new Gmail test and check Show original. SPF should show PASS for your domain or an aligned sender.

Turn on DKIM signing

DKIM is the Google Workspace setting teams often miss. Verifying the domain and creating users does not automatically mean Gmail is signing your outbound mail.

Open the Google Admin Console with a super admin account. Go to Apps · Google Workspace · Gmail · Authenticate email.

Select the domain. Use a 2048-bit key unless your DNS host cannot support long TXT values. Keep Google’s default selector unless you have a reason to change it.

Google commonly uses the selector google, which creates a DNS name like:

google._domainkey.yourdomain.com

The TXT value starts with:

v=DKIM1; k=rsa; p=...

Publish the exact host and value Google gives you.

DNS fieldValue
TypeTXT
Host or namegoogle._domainkey or the full host your DNS provider requires
ValueThe full DKIM value from Google
TTLDefault is fine

Return to Apps · Google Workspace · Gmail · Authenticate email and click Start authentication. Do not stop after adding DNS. Google Workspace must start signing after the record is visible.

Send a new test to Gmail. In Show original, DKIM should show PASS. Google’s current reference is here: turn on DKIM for Google Workspace.

If DKIM still fails, check that the selector matches, the TXT value was not split incorrectly, the record is on the right domain, and you tested from a Google Workspace mailbox on that domain.

Add DMARC alignment

DMARC tells receivers what to do when SPF or DKIM does not align with the visible From domain. It also gives you reports when you add a reporting address.

Start with monitoring unless you already know every legitimate sender is authenticated.

v=DMARC1; p=none; rua=mailto:dmarc@yourdomain.com

Use these DNS fields:

DNS fieldValue
TypeTXT
Host or name_dmarc
Valuev=DMARC1; p=none; rua=mailto:dmarc@yourdomain.com
TTLDefault is fine

Create the reporting mailbox before you use it. If you use a DMARC reporting service, use the address that service provides.

DMARC passes when either SPF or DKIM passes and aligns with the visible From domain. For Google Workspace, your normal mail should pass DKIM and DMARC after DKIM signing is active.

Do not jump straight to p=reject while you are still discovering old tools that send as your domain. A strict policy can block legitimate mail if those systems are not authenticated.

PhaseDMARC policyUse when
Monitorp=noneYou are discovering senders
Partial enforcementp=quarantineLegitimate senders are aligned
Full enforcementp=rejectYou are confident all real mail passes

For this spam problem, p=none is enough to prove alignment. Enforcement protects the domain, but it does not replace list quality or volume control.

What does Postmaster Tools show?

Google Postmaster Tools is the closest view you get into how Gmail sees your sending domain. It may not show data for every small sender every day, but it is still worth setting up.

Add your sending domain and verify ownership through DNS. Then review these areas once data appears:

Use Google’s official sender rules as the source of record: email sender guidelines. For account-level caps, check Google Workspace sending limits. Product editions, trial accounts and policy changes can affect those limits.

Do not panic over one thin day of data. Watch direction. If reputation moves from high to medium, or medium to low, slow down. If spam rate appears and rises, pause the campaign that caused it.

Complaint rate is the signal you can influence fastest. Remove weak prospects, stop sending to old lists, make the message clearly relevant, and reduce frequency. For bulk or marketing mail, follow Google’s unsubscribe requirements.

If Postmaster Tools shows authentication failures while your manual Gmail test passes, compare the source. Your Google Workspace mailbox may be fine while a CRM, campaign platform or support tool is still unauthenticated.

How much volume is safe?

Google’s sending limit is not your outreach target. Those limits prevent platform abuse. Deliverability usually breaks earlier, especially for cold outreach.

Use these ranges while repairing the account.

ItemNumber or rangeWhere to checkWhat to do
Google complaint targetUnder 0.10%; never 0.30% or higherGoogle Postmaster ToolsReduce volume before reputation drops
Existing domain warm-up14+ daysWarm-up dashboard and sent historyStart low and increase slowly
New domain warm-up3–4 weeksDomain age and sending historyDo not launch full campaigns early
BobWork warm-up start3 emails/dayMailbox warm-up settingsLet the ramp build naturally
BobWork default cap30/dayMailbox capKeep a steady background pattern
Campaign warm-up maintenance10–15/dayWarm-up capKeep signals steady during campaigns
Real cold outreach30–50/day/mailboxSent folder or campaign toolAdd mailboxes instead of forcing volume
Pause thresholdAbove 5% warm-up spam rate7-day sender spam ratePause for a few days and diagnose
Workspace user limitsCheck Google’s current limitsAdmin help and account editionDo not treat limits as safe outreach volume

For a new or quiet mailbox, use a slower sequence.

PeriodReal outboundWarm-upNotes
Days 1–30–10/dayLow rampTest records and mailbox access
Days 4–710–20/dayContinue rampSend only to strong-fit contacts
Days 8–1420–30/dayContinue rampWatch spam rate and replies
After day 1430–50/day10–15/dayAdd mailboxes for scale
New domainSlower than above3–4 weeksKeep campaigns conservative

Volume spikes are a common admin mistake. A mailbox that sent 12 messages per day last week should not send 200 tomorrow because a campaign is ready.

Scale horizontally. Use more properly configured mailboxes, each with moderate volume. Do not force one user to carry the whole campaign.

When should you use warm-up?

Warm-up helps when the technical base is correct and the mailbox needs a gradual, normal sending pattern. It is not a repair tool for broken authentication.

Warm-up is useful when:

Warm-up is not the fix when:

BobWork Email Warm-up can help once records pass. It is free, needs no credit card, and supports Gmail and Google Workspace. Outlook and Microsoft 365 are not supported yet.

The free pool does this step automatically by starting at 3 emails per day, adding 2 per day, and capping at 30 per day by default. You can edit the cap per mailbox up to 100.

For Google accounts, BobWork uses Google sign-in with the gmail.modify scope, or IMAP with an app password. Google may show an unverified-app notice because the CASA audit has not been completed.

Accounts warm in the shared network by default and can switch to a private pool, where only your own mailboxes write to each other (at least two needed). Accounts can connect up to 20 mailboxes.

During active campaigns, keep warm-up at 10–15 emails per day per mailbox. That keeps background activity steady without hiding campaign problems.

For the exact warm-up behaviour, see the engine rules. If this is your first mailbox, read what to expect when warming up.

What should you do now?

Work from fastest to slowest. This order prevents wasted time and avoids hiding the real cause.

StepActionHow to verify
1Send a test from the affected user to GmailGmail · More · Show original
2Check SPF at the root domainOne SPF record exists and includes Google
3Enable DKIM in Admin ConsoleDKIM shows PASS on a new test
4Add DMARC at _dmarcDMARC shows PASS, or the record is found
5Compare affected usersHeaders and sent volume differ by mailbox
6Add the domain to Postmaster ToolsDomain is verified and data appears when available
7Cut sudden campaign volumeSent count drops to a safer daily level
8Remove risky recipientsBounces and complaints stop rising
9Warm each mailbox gradually14+ days warming and stable spam rate
10Re-test after changesNew messages avoid spam more consistently

Use the free email blacklist checker if spam placement continues after authentication passes. A listing is not the first thing to assume for Google Workspace, but it is worth checking once the basics are clean.

You can also generate a conservative ramp with the email warm-up schedule generator. Keep the schedule mailbox-specific, not domain-wide.

Proof needs more than one inbox test. Confirm recovery across headers, placement, reputation and behaviour.

First, send new messages after each DNS change. Old mail will not update. In Gmail Show original, look for SPF PASS, DKIM PASS, DMARC PASS and a visible From domain that matches the authenticated domain.

Second, test more than one sender. If admin@ passes but alex@ fails, you have a user-level or sending-tool issue.

Third, check real placement over several days. You want steady delivery, replies from real recipients, low bounces and no complaint spikes.

Fourth, watch Postmaster Tools after enough volume exists. Data can lag or be unavailable for small senders, so do not expect instant confirmation. Direction matters more than one daily snapshot.

Fifth, check warm-up health. In BobWork, a mailbox is ready for outbound when it has warmed for 14+ days, has a 7-day spam rate of 3% or less, and has received at least 30 warm-up emails. Spam rate is measured directly in receiving mailboxes, not third-party seed lists.

If the domain is new, give it 3–4 weeks before judging full performance. Keep real outreach to 30–50 per mailbox per day once warmed. If you need more volume, add configured mailboxes instead of pushing one account harder.

If you want a simple next step, connect two Google Workspace mailboxes to the free warm-up tool. Fix SPF, DKIM and DMARC first, then let each mailbox build a measured sending pattern before you restart campaigns.

What else do senders ask?

Why are my Google Workspace emails going to spam?

Common causes are missing DKIM, broken SPF, no DMARC record, a new domain with no reputation, weak Postmaster Tools signals, poor list quality, or sudden per-user volume. Check authentication before changing copy or buying new domains.

Does Google Workspace need SPF, DKIM and DMARC?

Yes. Set SPF, turn on DKIM in the Admin Console, and publish DMARC at your DNS host. Google’s sender rules also expect authentication and low spam complaints, especially for higher-volume senders.

What SPF record should I use?

Use one SPF TXT record at the root domain that includes Google: v=spf1 include:_spf.google.com ~all. If other platforms send for your domain, merge them into the same SPF record. Do not publish multiple SPF records.

How long does DKIM take?

DNS can update within minutes, but allow time for propagation. After adding the Google DKIM TXT record, return to the Admin Console and start authentication. Then send a new Gmail test and check that DKIM shows PASS.

Can warm-up fix Workspace spam placement?

Warm-up helps after SPF, DKIM and DMARC are correct, especially for new domains or quiet mailboxes. It will not fix missing records, bad lists, complaint-heavy campaigns, misleading content, or unsafe sending volume.

What complaint rate is safe?

Google says to keep spam complaints below 0.10% and avoid reaching 0.30% or higher. Treat any visible rise in Postmaster Tools as a warning. Reduce volume, remove weak leads and pause risky campaigns.

How many cold emails per mailbox?

Keep real outbound volume much lower than Google’s account limits. A typical safe range is 30–50 real outreach emails per mailbox per day after warming. Add mailboxes for scale instead of pushing one user too hard.

Frequently asked questions

Why are my Google Workspace emails going to spam?

The common admin-side causes are missing DKIM, a broken SPF record, no DMARC record, a new domain with no sending history, poor Postmaster Tools reputation, or sudden per-user volume. Check authentication before changing copy or buying new domains.

Does Google Workspace need SPF, DKIM and DMARC?

Yes. For reliable delivery, set SPF, turn on DKIM in the Admin Console, and publish DMARC at your DNS host. Google’s sender rules also expect authentication and low spam complaints, especially for higher-volume senders.

What SPF record should I use for Google Workspace?

Use one SPF TXT record at your root domain that includes Google: v=spf1 include:_spf.google.com ~all. If other senders use your domain, merge them into the same SPF record. Do not publish multiple SPF records.

How long does DKIM take to work?

DNS can update within minutes, but allow up to 48 hours. After adding the Google DKIM TXT record, return to the Admin Console and start authentication. Then send a test to Gmail and check that DKIM shows PASS in the message headers.

Can warm-up fix Google Workspace emails going to spam?

Warm-up helps after SPF, DKIM and DMARC are correct, especially for new domains or quiet mailboxes. It will not fix missing records, bad lists, complaint-heavy campaigns, misleading content, or a mailbox that is already exceeding safe sending volume.

What complaint rate is safe for Gmail?

Google says to keep spam complaints below 0.10% and avoid reaching 0.30% or higher. Treat any visible rise in Postmaster Tools as a warning. Reduce volume, remove weak leads and pause risky campaigns before reputation drops further.

How many cold emails should I send per Google Workspace mailbox?

For cold outreach, keep real outbound volume much lower than Google’s account limits. A typical safe range is 30–50 real outreach emails per mailbox per day, after warming. Add mailboxes for scale instead of pushing one user too hard.

Records fixed? Rebuild the reputation

Warm-up is the part you cannot do by hand for two weeks. The free pool sends, replies and rescues from Spam for you.

Start free