All articles
September 28, 2026·10 min read

How to Set Up Google for Nonprofits for Your Church (Step by Step, With Screenshots)

By Pastor Eli

Earlier this month I spent an afternoon on Messenger walking a pastor through setting up Google for his church. He was on his laptop, I was on my phone, and he sent me a photo of every screen as he went. By the end his church had free professional email on its own domain, email signing set up so its messages don't land in spam, and applications in for Google's free advertising grant.

It took us a couple of sittings. It shouldn't have. Nothing we did was hard. Google just doesn't tell you what order to do things in, and it uses words like TXT record and DKIM as if every pastor has an IT department.

So here's the whole thing, using the photos he sent me. If you've been putting this off, this is the evening to do it.

What Your Church Gets (Free)

Once you're approved for Google for Nonprofits, you can switch on:

  • Google Workspace for Nonprofits. Real email addresses like pastor@yourchurch.com instead of firstbaptist1987@gmail.com, plus shared Drive, Calendar, Meet, and Docs for your staff and volunteers. It's free.
  • Google Ad Grants. Up to $10,000 a month in Google Search ads, so when someone in your town searches church near me or grief support, your church can show up.
  • YouTube Nonprofit features. Donation links and a few extra tools on your church's channel.

The email alone is worth it. A church email on your own domain looks trustworthy, isn't tied to one person's personal Gmail, and doesn't get lost when a secretary or youth pastor moves on.

Before You Start: Have These Three Things Ready

  1. Your domain login. This is wherever your church's web address (yourchurch.com) is managed: GoDaddy, Squarespace, Cloudflare, Wix, AWS, or wherever it was bought. If you don't know, ask whoever built your website. This is where most people get stuck, so find it first.
  2. Your church's legal name and EIN. They need to match what the IRS (or your state) has on file.
  3. One Google account the church will own. Ideally not your personal Gmail. More on this in the snags below.

Step 1: Get Your Church Approved for Google for Nonprofits

Go to google.com/nonprofits and click Get started. You'll enter your church's details, and Google's verification partner, Goodstack, will confirm you're a genuine nonprofit.

A note for churches: many congregations aren't listed in the IRS database, because churches don't have to apply for recognition to be tax-exempt. If Goodstack can't find you automatically, it will ask for proof. Upload your IRS determination letter if you have one, or your articles of incorporation. This can take a few days, so start it first.

Step 2: Request Google Workspace for Nonprofits

Once you're approved, open your Google for Nonprofits account and choose Google Workspace for Nonprofits. You'll see this four-step card:

Google Workspace for Nonprofits activation card listing four steps: start your Google Workspace setup, verify your domain, submit your domain name, and wait for review. A red error under the domain field says the Google Workspace domain is not verified.
The four-step card. Notice the red message: he typed in his domain before verifying it, which is the most common first mistake.

Do these in order. Click Start your Google Workspace for Nonprofits setup (step 1) first. This creates your Workspace account and admin login. Then verify your domain (step 2). Only then come back and type your domain into the box and click Activate.

If you type the domain in too early, you'll get the red "Your Google Workspace domain is not verified" message in the photo above. It's harmless. Finish the next steps and resubmit.

Step 3: Verify You Own Your Domain

After creating the Workspace account, you'll land in the Google Admin console with a red banner across the top:

Google Admin console for the church showing a red warning banner: You could lose access to your account soon because your domain isn't verified, with a Verify button.
Don't panic about "you could lose access." Google is just telling you the next step. Click Verify.

Click Verify. Google lays out the two jobs ahead: prove you own the domain, then turn on Gmail.

Google Workspace 'Let's set up your domain' screen with two steps: verify you own the domain (5 minutes) and start using Gmail with your domain (10 minutes), and a Get started button.
Two jobs, about fifteen minutes total if you have your domain login handy.

Click Get started, then pick where your domain is managed from the dropdown:

Domain host dropdown open, listing Amazon Web Services, Bluehost, Cloudflare, ClouDNS, DreamHost, and GoDaddy.
Pick your domain host. If yours isn't listed, scroll to the bottom and choose "Other."

Next Google shows you a verification code. This is a line of text you'll paste into your domain's settings to prove the domain is yours.

Add verification code screen showing a TXT record with Record name set to default value, a Value field containing the verification code with a copy icon, and TTL set to lowest possible value.
The verification code. The value is blurred here. Yours will start with google-site-verification=.

In another tab, log in to your domain host and find the DNS settings (sometimes called DNS records, Manage DNS, or Advanced DNS). Add a new record:

  • Type: TXT
  • Name / Host: leave it blank, or type @. This is what Google means by "Set to default value."
  • Value: click the copy icon next to the code in Google, then paste it here
  • TTL: the lowest option available

Save it, go back to Google, tick "Come back here and confirm once you have updated the code," and click Confirm.

The same verification screen scrolled down, with the confirmation checkbox ticked and the Confirm button enabled, next to a Go to AWS button.
Tick the box, then Confirm. The "Go to AWS" button appears because this church's domain lives on Amazon. Yours will name your own host.

Sometimes it goes through right away. Sometimes Google needs a few minutes to see the change. If it says it can't find the code, wait fifteen minutes and click Confirm again. When it works, you'll see this:

Google Workspace screen reading 'Your domain is verified!' with a green check next to the domain and a button labelled Activate Gmail.
Domain verified. One job done.

Step 4: Turn On Gmail for Your Domain

Click Activate Gmail. Google first asks you to list every email address that already exists on your domain, so nobody's mail gets cut off during the switch:

Activate Gmail for everyone screen showing a Users list with the pastor's account (blurred), an Add user link, and a Proceed with activation button.
If your church already has other addresses on this domain (office@, youth@), add them here before you proceed.

This matters more than it looks. When you finish this step, all email to your domain starts flowing to Google. If your secretary has an existing office@yourchurch.com address somewhere else and you don't add her here, her mail will stop arriving.

Click Proceed with activation. Google gives you an MX record, which tells the internet where to deliver your church's mail:

Activate Gmail MX record screen showing Priority 1, Value SMTP.GOOGLE.COM, TTL set to lowest possible value, and the confirmation checkbox ticked.
One MX record: priority 1, value SMTP.GOOGLE.COM.

Back at your domain host, add:

  • Type: MX
  • Name / Host: blank or @
  • Priority: 1
  • Value / Points to: smtp.google.com. Some hosts want a period on the end (smtp.google.com.), as Google's note says.

Then delete any old MX records that point somewhere else. Leftover MX records are the number one reason "my new email isn't getting anything." Confirm in Google, and:

Google Workspace screen reading 'Gmail is activated!' with confirmations that the domain is verified and Gmail is ready, noting it can take up to 24 hours for all new email to arrive.
Gmail is on. It can take up to a day for every sender's mail to find its new home.

Step 5: Set Up DKIM So Your Emails Don't Go to Spam

Most guides skip this step, and it's the one we got stuck on.

DKIM is a digital signature attached to every email your church sends. It proves the message really came from yourchurch.com and wasn't forged. Without it, Gmail, Outlook, and Yahoo are more likely to treat your church newsletter as suspicious and file it in spam.

Google walks you into DKIM setup right after Gmail. Leave the key length at 2048 and click Generate key:

DKIM setup screen titled Add verification key, with Key bit length set to 2048 and a Generate key button.
Keep 2048. Only choose 1024 if your domain host rejects the longer key.

Google produces a record name and a very long value:

DKIM key generated, showing Record name google._domainkey, a long key value (blurred), TTL set to lowest possible value, and a Go to AWS button.
Record name google._domainkey, and a key several lines long (blurred here). Use the copy icon.

Add it at your domain host as:

  • Type: TXT
  • Name / Host: google._domainkey
  • Value: the whole key, starting with v=DKIM1;

Here's where we got stuck. The pastor sent me a photo of this screen so I could add the record for him. But you can't copy text out of a photo, and a key this long can't be retyped without a mistake. One wrong character and the signature silently fails. What finally worked was having him click the copy icon on his own computer and email me the text.

If someone else manages your domain, do the same: copy and paste the key into an email or text. Don't send a screenshot.

Two more tips:

  • Some hosts choke on long keys. Amazon's Route 53 and a few others limit each piece of text to 255 characters. If yours complains, split the key into two quoted chunks ("first half" "second half"), or generate a 1024-bit key instead.
  • Don't generate a new key halfway through. Each click of Generate new key makes the old one useless. If you've already sent it to someone or pasted it, stick with that one.

Tick the confirmation box and click Confirm. Google checks the record:

Google Workspace screen reading 'Getting your domain ready' with a timer icon: This can take a few minutes. Leave this page open while the key is being added.
Leave the page open. If it times out, don't worry: DNS can take up to 48 hours to catch up. Come back later and turn on authentication in the Admin console.

If it doesn't finish, you can come back any time: Admin console → Apps → Google Workspace → Gmail → Authenticate email → Start authentication.

Also add an SPF record. The wizard didn't ask for this one, but you should add it anyway. It's another TXT record at @ with the value v=spf1 include:_spf.google.com ~all. It lists Google as allowed to send mail for your domain. If you already have an SPF record (from a website form service, for example), don't add a second one. Add include:_spf.google.com to the existing one.

Step 6: Submit Your Domain and Wait

Now go back to Google for Nonprofits, open the Workspace card from Step 2, type your domain, and click Activate. This time there's no red error. You'll see:

Google for Nonprofits products page showing Google Workspace for Nonprofits and Google Ad Grants, each with Status: Activation request received, which can take several days to review.
"Activation request received" on both Workspace and Ad Grants. Now you wait a few business days.

Google reviews the request (it says up to 3 business days) and emails you when you're approved. Until then your Workspace runs on a trial, which is fine. Your email already works.

The Snags We Hit (So You Don't)

  • Signed in as the wrong person. Look at the address bar: the pastor's said /u/2/, which means he was signed in to three Google accounts at once and was on the third. Half our confusion was him being on gmail.com in one account and admin.google.com in another. Do this in a private/incognito window or a separate browser profile, signed in only as the church's admin.
  • Typing the domain before verifying it. It gives you the red error from Step 2. Verify first, then submit.
  • Sending a screenshot of a key. Copy and paste. Always.
  • Forgetting existing addresses. List every current address on your domain before activating Gmail, or mail to them stops.
  • Old MX records left behind. Delete them.
  • Browser pop-ups covering the page. His browser kept showing a shopping "cash back" pop-up right over the Google buttons. Close it or click Do not show. It has nothing to do with Google.

One More Thing: Ad Grants Will Look at Your Website

A few days later, the pastor's Ad Grants request came back with this:

Google Ad Grants card reading 'Your activation request needs work': the organization's website doesn't meet the Ad Grants website policy. Change the website to load quickly and have clear navigation. Include substantial, up-to-date content and calls-to-action.
Sent back: "Change the website to load quickly and have clear navigation. Include substantial, up-to-date content and calls-to-action."

This is very common. Google isn't going to give $10,000 a month in free ads to send people to a page that's slow, out of date, or doesn't tell a visitor what to do next. It wants a real site: current service times, what to expect on a first visit, ministries with actual descriptions, and a clear way to plan a visit or get in touch.

If that's where you are, fix the website first, then resubmit from the same Ad Grants card. If you're not sure how your site measures up, the free Church Website Score will tell you in about a minute what Google (and a first-time visitor) sees.

It's Worth the Afternoon

None of this is ministry, exactly. But it clears the way for ministry. A church email that reaches people's inboxes, a shared calendar your volunteers can actually find, and a search ad that puts your church in front of someone typing "church near me" at midnight all keep the door open a little wider.

Get it done in one sitting if you can: approval first, then domain, Gmail, and DKIM. And if you get stuck on a screen, send the person helping you the text, not the photo.

Common questions
Can a church get Google for Nonprofits?
Yes. Churches can apply the same way any charity does. Google uses a partner called Goodstack to confirm you're a real nonprofit. Many churches aren't listed in the IRS database, because churches don't have to apply for tax-exempt status, so Goodstack may ask you for a document such as your determination letter or articles of incorporation.
Is Google Workspace really free for churches?
The Google Workspace for Nonprofits edition is free once your church is approved. It covers Gmail on your own domain, plus Drive, Calendar, Meet, and Docs. Google also offers paid editions to nonprofits at a discount if you ever need more.
What is a DKIM key and do I need it?
DKIM is a digital signature that proves an email really came from your church's domain. Without it, your emails are more likely to land in spam. Google generates the key for you. You copy it into your domain's DNS settings as a TXT record named google._domainkey. Always use the copy button, never retype it.
Why was our Google Ad Grants application rejected?
The most common reason is the website. Google requires an Ad Grants site that loads quickly, has clear navigation, has substantial and current content, and tells visitors what to do next. Fix the site, then submit it again from your Google for Nonprofits account.

Written by Pastor Eli, in hopes of being a help to your ministry.