Church Plant Media can help set up SPF, DKIM, and DMARC for your church's email domain. These settings help receiving email services verify your messages and protect against someone impersonating your domain. Learn more about Google's email authentication recommendations.
To complete the setup, we need access to Google Workspace and your domain's DNS settings. Follow these steps to create a separate account for the Church Plant Media team member assisting you.
Before you begin
Make sure you have:
- Access to your church's Google Workspace Super Admin account.
- The name and email address of the Church Plant Media team member provided in your support ticket.
- The domain you use for email and the name of the company managing its DNS records, if known.
Google requires a Super Admin to generate a DKIM key. This role provides broad administrative access to your organization, so grant it temporarily and remove it when our work is complete. See Google's DKIM setup guide.
1. Create a separate user account
Adding a user may increase your bill, depending on your plan and license settings. Check these before creating the account. We'll only need access for a few days. Your cost depends on your plan; see the account-removal and billing guidance at the end of this article. See Google's guide to adding a user.
- Sign in to the Google Admin console with your Super Admin account.
- Open Directory > Users and select Add new user.
- Enter the name of the Church Plant Media team member assisting you.
- Choose a new Primary email address on your church's domain, such as
cpm@example.org. Replaceexample.orgwith your own domain. - For Secondary email, enter the Church Plant Media email address from your support ticket.
- Select Add New User.
- Select Preview And Send to send the account setup information to that Church Plant Media email address, then select Done.
This creates a user within your organization. The secondary email receives the setup information; it does not become the account's sign-in address.
Reply to your support ticket to let us know the account is created. Wait for our team member to sign in and set up 2-Step Verification before assigning admin access. Google's administrator verification requirements can apply immediately when a user becomes an admin. See Google's explanation of 2-Step Verification enforcement.
Do not send us your personal account password or verification codes.
2. Grant temporary Super Admin access
Once our team confirms the new account is ready:
- In Directory > Users, select the new user's name.
- Open Admin roles and privileges.
- Select the Super Admin role.
- Move its slider to Assigned and select Save.
Keep your own Super Admin role assigned so your church retains control. New admin permissions usually take effect within minutes, but Google advises allowing up to 24 hours. See Google's instructions for making a user an admin.
3. Arrange access to your DNS records
Google Workspace access lets us generate the DKIM record and turn on DKIM signing. The DNS records for SPF, DKIM, and DMARC must also be added or updated wherever your domain's DNS is hosted. Google's guides explain the DNS requirements for SPF, DKIM, and DMARC.
We will let you know who your DNS host is and coordinate with you to grant us access.
4. Let us know you're ready
Reply to your Church Plant Media support ticket with:
- The new Google Workspace username and confirmation that you assigned Super Admin access.
- Any other services that send email using your church's domain, such as a newsletter platform, church management software, or website forms.
Other email senders need to be included in our review so legitimate messages continue to authenticate correctly. See Google's guidance on third-party email and DMARC.
We'll confirm access, review the existing settings, and coordinate the updates. If Gmail was recently activated for your organization, Google requires a 24–72 hour wait before a DKIM key can be generated. See Google's DKIM setup guide.
5. Delete our temporary account after setup
Once we confirm that setup is complete, delete the dedicated user account you created for Church Plant Media. Keep your own administrator account.
Removing admin access or suspending the account does not stop license charges. Google continues billing for suspended users. See Google's account suspension guide.
- Sign in to the Google Admin console with your own Super Admin account and open Directory > Users.
- Select the temporary Church Plant Media user, open Admin roles and privileges, turn off its admin roles, and select Save.
- Save or transfer any email, files, or calendar data your church needs from this account before deleting it. Data that is not preserved may be lost.
- Return to Directory > Users, point to the temporary account, and select More options > Delete user.
- Follow Google's data-transfer prompts, then select Delete User to confirm. Choose Don't transfer data only if you have confirmed there is nothing you need to keep.
For details, see Google's instructions for deleting a user.
Check how this affects your bill
- Flexible Plan: Deleting the account stops future per-user charges for that account. Google still bills for the time it existed, prorated for the billing period. See Google's billing guide.
- Annual/Fixed-Term Plan: Deleting the account does not reduce your current charges or committed license count, even if you pay monthly. To avoid renewing an unused license, go to Billing > Subscriptions, open your subscription, and under Renewal options select Change > Auto-renew my contract with fewer licenses, then Save. The reduction takes effect at renewal. See Google's guide to reducing licenses.
If you purchase Google Workspace through a reseller, contact them to confirm how deleting the account affects your bill.
Deleting our temporary user does not undo the SPF, DKIM, and DMARC setup. Leave those DNS records in place and keep DKIM authentication enabled.