DNS and Google Workspace Email Safety
Document: INF-204Type: RunbookStatus: ApprovedOwner: Cloud Engineering / Workspace AdminVersion: 4.2.0Updated: 2026-07-17
Records that must be preservedโ
| Record family | Purpose | Risk if missing |
|---|---|---|
| MX | Routes incoming mail to Google Workspace | Inbound mail failure |
| SPF TXT | Authorizes sending systems | Spam placement or spoofing risk |
| DKIM TXT | Cryptographic mail authentication | Authentication failure |
| DMARC TXT | Mail policy and reporting | Reduced protection and visibility |
| Google verification TXT/CNAME | Proves domain ownership | Administration and verification issues |
Migration checklistโ
Export DNS before changes. Compare every MX value and priority. Preserve SPF as a single valid record. Preserve DKIM selector records. Preserve DMARC policy. Test inbound and outbound mail after nameserver change.
Mail testโ
- Send an external message to
hello@cloudberrie.com. - Confirm receipt in the primary inbox and correct Gmail label.
- Reply using the alias and confirm the external recipient sees the alias.
- Send to
accounts@andengineering@as additional routing tests.