DMARCmetric

Add a DMARC record in Cloud DNS or Squarespace

Updated 2026-09-30 · Setup Guides

If your domain's nameservers look like ns-cloud-a1.googledomains.com, its DNS runs on Google's Cloud DNS infrastructure — and two different panels use those nameservers. Squarespace Domains, which took over Google Domains, lists .googledomains.com among its own default nameservers; Google Cloud DNS uses them for zones in a Google Cloud project. We found no public signal that tells the two apart, so this guide covers both:

One more case. Google says that a domain in Cloud Domains that still uses the old Google Domains DNS can't have its DNS records changed, and points to exporting them to Cloud DNS or another DNS provider. If neither panel lets you edit the domain's records, that's the likely reason — its DNS has to move somewhere you can edit it before you can publish DMARC.

The record you're publishing

FieldSquarespaceGoogle Cloud DNS
TypeTXTTXT
Name_dmarc_dmarc
Valuev=DMARC1; p=none; rua=mailto:…"v=DMARC1; p=none; rua=mailto:…" (inside double quotes)

The Value is your DMARC policy. If you're setting up monitoring with DMARCmetric, Add your first domain generates the full value for you, including your workspace's unique rua= reporting address — copy it from the wizard with the copy button rather than retyping it. p=none is the right starting policy: it monitors everything and blocks nothing.

The quotes differ by panel. Google Cloud DNS documents TXT values as strings enclosed in quotation marks, and a value with spaces — a DMARC record has several — must use the quoted form. Squarespace's steps enter the value as your service gives it, and DMARCmetric's has no quotes.

The steps below add a new record, for a domain with no DMARC record yet. If _dmarc already has one, don't add another — edit the one you have instead.

In Squarespace, check first: a Squarespace domain can have only one DMARC record, and Squarespace adds one for you when you create an email forwarding rule.

Step by step in Squarespace

  1. Open your domains dashboard at account.squarespace.com/domains and select the domain.
  2. Click DNS, then DNS Settings.
  3. Scroll down to Custom Records. If a TXT record named _dmarc is already listed, edit it instead.
  4. Click Add record (Squarespace may ask for your password first), and in the Type menu select TXT.
  5. In Name, enter _dmarc — without your domain at the end. Squarespace adds your domain for you.
  6. In Text, paste your v=DMARC1; … value as it is, without quotes.
  7. Click Save.

Squarespace says changes to your records can take 24 to 48 hours, and its custom records use a 4-hour TTL by default.

Step by step in Google Cloud DNS

  1. In the Google Cloud console, go to the Cloud DNS zones page and click the name of your domain's zone.
  2. On the Zone details page, click Add standard.
  3. In DNS name, enter _dmarc — only the part in front of your domain, the way Google's own guide enters a subdomain like mail.
  4. For Resource record type, select TXT.
  5. Enter a TTL and choose its unit.
  6. In the record's data field, enter your value inside double quotes: "v=DMARC1; p=none; rua=mailto:…".
  7. Click Create.

Google says a change is first pushed to Cloud DNS's own servers, and resolvers elsewhere pick it up when their cached answer expires.

If you already have a DMARC record

A domain can have only one DMARC record, so don't add a new record — change the one that's there. Never add a second _dmarc record next to the old one: with two, email providers ignore both.

  1. Find the existing TXT record at _dmarc — under Custom Records in Squarespace, or in the zone's list of record sets in Cloud DNS.
  2. Edit that record.
  3. What you change depends on what DMARCmetric shows you — check which of these two it is before you touch anything:
    • If DMARCmetric shows only an address (mailto:rua+…, shown when it couldn't read your DNS at that moment), don't replace anything. Add that address to your existing rua= tag, separated by a comma. If the record has no rua= tag, add one: rua= followed by the address, separated from the tag before it by a semicolon. Leave your policy and every other tag as they are.
    • If DMARCmetric shows a full record (starting with v=DMARC1), replace the record's whole value with it. That value is built from your existing record: your policy and tags are kept, and it includes your DMARCmetric reporting address. Keep the value inside double quotes in Cloud DNS: "v=DMARC1; …" — in Squarespace, leave the quotes out.
  4. Save the record.

If there are several. In Cloud DNS, several values at one name are items of one record set: if it has more than one item holding a v=DMARC1 value, delete the extra items and keep one, then change the one you keep exactly as in step 3: if DMARCmetric shows a full record, that item becomes it; if it shows only an address, add the address to its rua= tag. Squarespace allows only one DMARC record. Until only one is left, receivers treat the domain as having no DMARC policy at all.

Verify it's live

From a terminal:

dig TXT _dmarc.example.com +short

You should see your v=DMARC1; … value echoed back in quotes. No terminal handy? Run your domain through the free DMARC checker — it fetches the live record and validates the syntax, which dig won't do. And if you added the record as part of DMARCmetric onboarding, press Verify DNS in the wizard; Verify your domain explains each result it can give you.

Common mistakes

If some of your domains live at other providers, the same record works everywhere — the Cloudflare and GoDaddy walkthroughs cover those panels.

Still stuck?

We answer every message — usually within one business day.

Email [email protected]