Google Workspace ยท How-to

Google Workspace setup: from domain verification to a working inbox

Setting up Google Workspace is four DNS records and about a dozen console settings. The records are the part people get wrong, so this guide puts the exact values first, then the order to do everything in, then the settings that decide whether the account is safe to hand to staff.

Follow it top to bottom for a new domain. If you are moving an existing mail system rather than starting fresh, do the DNS work here but read the migration guide first, because the order of operations changes when there is old mail to protect.

Updated 9 Sep 2026 Written and reviewed by the WebsNP team 11 min read

The DNS records, in full

These are Google's published values. Host names are written as most DNS panels expect them: some panels want the bare domain, some want an @ symbol, and a few want the full domain with a trailing dot. Priority applies only to the MX record.

PurposeTypeHostValueNotes
Domain verificationTXT@ (the domain root) the google-site-verification string from your Admin console Unique to your account. Active in about 10 minutes
Mail deliveryMX@ (the domain root) smtp.google.com, priority 1 One record only. Delete every old MX record. Up to 72 hours to propagate
SPFTXT@ (the domain root) v=spf1 include:_spf.google.com ~all One SPF record per domain. Merge, never duplicate
DKIMTXTgoogle._domainkey the 2048-bit key generated in the Admin console Selector is google. Generate after Gmail has been running 24 to 72 hours
DMARCTXT_dmarc v=DMARC1; p=none; rua=mailto:your-report-address Start at p=none, then quarantine, then reject

Older Google setups used five MX records beginning aspmx.l.google.com. Those still work, so an existing domain does not have to be changed. For a new setup, use the single smtp.google.com record at priority 1 and nothing else, because a stray old MX record left in the zone is the most common cause of mail that arrives for some people and not others.

Do it in this order

  1. Confirm you control the DNS. Before anything else, log in to the panel that holds the zone and check you can add a TXT record. If you cannot get in, that is the real first task, and it is worth solving before you buy licences.
  2. Create the account and choose the edition. Sign up with a company address you will keep, not a personal Gmail belonging to one director. Google offers a 14-day free trial for up to 10 users if you want to test before committing.
  3. Add and verify the domain. Copy the TXT verification string from the Admin console into the zone. The record is usually live in about 10 minutes and Google's confirmation is normally quick, up to an hour. Nothing about verification affects your existing email, so this is a safe step to take early.
  4. Create the users. Agree a naming convention first and apply it to everyone: firstname@ or firstname.lastname@ is easier to live with than a mix. Set each account to require a password change at first sign-in.
  5. Create groups and aliases. Decide which shared addresses are groups and which are aliases before you make them. This distinction is the one worth understanding properly, and it is covered below.
  6. Point MX at Google. Remove every existing MX record, add the single smtp.google.com record at priority 1, and save. Allow up to 72 hours for full propagation, although most senders switch within a few hours.
  7. Add SPF. Publish v=spf1 include:_spf.google.com ~all as a TXT record at the domain root. If you already have an SPF record for a website or a billing system, merge the include into that single record rather than publishing a second one.
  8. Wait, then add DKIM. Google asks you to let Gmail run for 24 to 72 hours before generating the DKIM key. Then generate a 2048-bit key in the Admin console, publish it at google._domainkey and switch authentication on in the console after the record resolves.
  9. Add DMARC. Publish a TXT record at _dmarc with p=none and a reporting address. Read the reports for a few weeks to find anything else sending as your domain, then tighten to quarantine and eventually to reject.
  10. Configure the console settings. Organisational units, 2-Step Verification, recovery options, endpoint basics, Drive sharing and the Gemini app, all covered in the sections below.
  11. Set up devices. Phones and desktop clients last, once mail is actually flowing, so nobody configures a client against a domain that is not ready.
  12. Run the checks. The final section lists what to test before you tell the whole company the new email is live.

If you send more than 5,000 messages a day from your domain, all three of SPF, DKIM and DMARC are required rather than advisable. Even at ordinary volumes, publishing all three is what keeps your invoices and quotations out of customers' spam folders.

Where your DNS actually lives

Records go wherever your nameservers point, which is not always where you bought the domain. Three situations cover most businesses in Nepal.

A .com.np domain is registered free through Mercantile's register.com.np. The registration and the DNS are separate questions: the records live in whichever panel the nameservers point to, which may be register.com.np itself, your hosting cPanel or Cloudflare. Check the nameservers first and edit in the right place, otherwise you will add perfect records to a zone nobody is reading.

A domain using your hosting nameservers keeps its zone in cPanel, under Zone Editor. Editing MX there sometimes also changes cPanel's own local mail routing setting, so if mail behaves oddly after cutover, check that the domain is set to remote rather than local mail exchanger.

A domain on Cloudflare has its records in the Cloudflare dashboard. MX and TXT records are never proxied, so leave the cloud icon grey for them.

Users, groups, aliases and organisational units

These four things are often confused, and the confusion costs money because people create paid accounts for addresses that do not need one.

A user is a person with a licence, a mailbox and a password. An alias is another address that delivers into an existing user's mailbox at no extra cost, useful for spelling variants and for a one-person role. A group is an address that delivers to several people, which is what sales, info and support addresses should almost always be: it costs nothing, it survives staff changes and you add or remove members without touching anyone's password. An organisational unit is a folder of users that lets you apply different settings to different parts of the company, for example allowing external Drive sharing for the sales team but not for accounts.

Get this right at setup and you will not be paying for empty mailboxes a year later. If you are starting from scratch and want the domain and addresses planned together, the domain email guide walks through that decision in more detail.

Security settings to do on day one

Every Business edition includes the controls below, so there is no reason to leave them for later.

2-Step Verification

Turn it on, give staff an enrolment period, then enforce it. Enforce it for admin accounts immediately. This single setting prevents most account takeovers.

Recovery details

Add a recovery phone and address to the super admin account and check every user has theirs set. An admin locked out of a domain with no recovery route is a slow problem to solve.

A second super admin

Create one, kept by a different person, and use ordinary accounts for daily work. Never run the company from a single admin login.

Basic endpoint management

Included in every Business edition. It registers the phones holding company mail so a lost device can be wiped of its work account.

Gmail safety settings

Review the spam, phishing and malware settings and switch on the enhanced pre-delivery scanning and attachment protections.

Alerts and audit logs

Point admin alerts at an address someone reads, so a suspicious login is noticed the same day rather than at the next audit.

Our security page covers what each edition adds beyond this, including Vault and advanced endpoint management on Business Plus.

Drive sharing defaults

Drive's external sharing setting is worth deciding deliberately, because the default shapes how carelessly files leave the company. The choices are to allow sharing outside the organisation, to allow it with a warning, to restrict it to trusted domains or to switch it off. Most businesses land on allowing external sharing with warnings, and setting new files to be visible only to named people rather than to anyone with the link.

Set up Shared Drives at the same time, one per function such as accounts, projects or HR. Files in a Shared Drive belong to the organisation rather than to the person who created them, which is exactly what you want when someone leaves.

Turning on the Gemini app

Gemini features are included in Business editions rather than sold as an add-on, but the Gemini app itself is an admin decision. Switch it on under Generative AI, then Gemini app, in the Admin console. Users must be 18 or older. What each edition includes differs: Business Starter gets Gemini in Gmail and the Gemini app at Standard access, while Standard and Plus add Gemini in Docs, Sheets, Slides and Meet, with the app at Pro access. That difference matters, because at Standard access chats may be reviewed by people and used to improve Google's models, which is not what you want staff pasting client documents into.

Phones and Outlook

On Android and iPhone, the Gmail app signs in with the work address and needs no manual server settings. Add Google Calendar and Drive at the same time so people are not switching between apps to find a file. If a phone is enrolled in endpoint management, the user will be asked to accept the profile.

Outlook and other desktop clients connect over IMAP, which has to be enabled in Gmail settings for the account. It works, but it is worth asking whether it should be the default: staff on Outlook miss labels, search speed and the Gemini features you are paying for. Where Outlook is genuinely required, expect to reconfigure it per machine.

Final checks before you announce it

  1. Send and receive both ways. Test from a new account to an outside address and back, including at least one message with an attachment.
  2. Inspect the headers. On a received message, view the original and confirm SPF and DKIM both show as passing. If they do not, the records are wrong or DKIM was not switched on in the console after publishing the key.
  3. Test every shared address. Mail each group and alias from outside the company and confirm the right people receive it.
  4. Check for leftover records. Look for old MX entries, a second SPF record or an obsolete autodiscover record. Any of these will cause intermittent delivery problems weeks later.
  5. Confirm anything else that sends as your domain. Website contact forms, invoicing software and CRM systems all need their sending settings reviewed.
  6. Sign in as an ordinary user. Check that 2-Step Verification prompts correctly and that the person can reach Drive, Calendar and Meet.

If something is not right at this stage, the symptoms are usually diagnosable from the message headers. Our notes on fixing common Workspace email problems cover the usual suspects.

Doing it yourself, or not

None of this is difficult. It is simply a sequence with a couple of steps that have to happen in order and one 24 to 72 hour wait in the middle. Someone comfortable in a DNS panel can complete a small setup in an afternoon plus the DKIM wait.

WebsNP performs this setup for its Workspace customers, including domain verification, the MX, SPF, DKIM and DMARC records and user creation, and bills in NPR. Licences start with Business Starter at $2.78 per user per month. If you would rather hand over the DNS work, talk to us with your domain name and the number of accounts you need.

Frequently asked questions

How long does the whole setup take?

The console work takes an afternoon for a small team. The waits are outside your control: domain verification is normally active in about 10 minutes, MX propagation can take up to 72 hours, and Google asks you to wait 24 to 72 hours after Gmail starts working before generating the DKIM key.

Do I still need the five aspmx MX records?

No. Google's current instruction is a single MX record at the domain root with the value smtp.google.com and priority 1. The older aspmx.l.google.com records still work for domains that already have them, so there is no urgency to change a working setup, but new setups should use the single record.

Why can I not add DKIM straight away?

Google asks you to let Gmail run for 24 to 72 hours before generating the 2048-bit DKIM key for the selector named google. Generate it in the Admin console after that wait, publish the TXT record, then switch authentication on in the console once the record resolves.

Where do I add records for a .com.np domain?

Wherever your nameservers point. A .com.np domain is registered through register.com.np, but the DNS zone may be hosted there, in your hosting cPanel or in Cloudflare. Check the nameservers on the domain first, then add the records in that panel.

Should info and sales be users or groups?

Groups, in almost every case. A group costs nothing, delivers to several people and keeps working when staff change. Create paid user accounts only for real people, and use aliases for spelling variants of an individual's address.

Is there a free trial?

Google offers a 14-day free trial for up to 10 users when you sign up directly. It is a reasonable way to test an import or check that a mail client behaves before committing to a plan.

Sources and further reading

Product facts on this page were checked against Google's own documentation on the date shown above. Google changes plan contents, limits and country availability over time, so treat the official pages as the final word.