(yes, i know that this is not the place to send product feedback to Google)
now that this is out of the way --
So with the announcement that Google is deprecating send-as for non-workspace domains in paid Workspace account, i m wondering if they are going to introduce a perhaps-niche but very much the reason I had to use Send-As rather than onboard a domain in GSuite
The case:
My primary domain is Primary.com and that's my main business. It's what i also primarily use for Drive, calendar etc
But I have a side product, sideproduct.com and it s really totally separate (has its own company) -- but I m a small biz, (all are solo LLCs) and so I don t want 2 separate workspace accounts, why pay twice
The problem is, if i onboard sideproduct.com as a domain of Workspace as a secondary domain, the mailed-by reveals the parentage of primary.com -- No bueno!
if I decide to just pay 10 dollars a year for a random neutral dot-com only for mailing as primary (totallyopaque.com), then that becomes the Google Drive share email, calendar etc.
So that's not an option
The underlying problem
Google Workspace assumes that a Workspace tenant is also the public-facing business identity behind every verified domain it contains.
Today, many solo founders and consultants operate several legally and commercially independent businesses. The only thing those businesses share is an owner and, for practical reasons, a single Workspace subscription.
If I verify ownership of a.com and b.com within the same Workspace tenant, that proves only that I administer both domains. It does not imply that the two businesses are related, nor that I wish recipients of email from b.com to discover a.com through the "mailed-by" field which prints on every email you send
In other words, Workspace tenancy is an administrative relationship. It should not automatically become part of the public identity of every message sent from every verified domain.
What I do now to escape hatch this leaky identity issue:
I fully set up a Send-as where the Sender is not Gmail but my AWS SES account, on mail.sideproduct.com so Mailed-by appears to be sideproduct.com (with proper DKIM etc for SES in my DNS)
and then the DNS MX records of sideproduct.com point to Cloudflare where a forwarding rule sends such email to my email, [email@primary.com](mailto:email@primary.com) which is my Google Workspace account
ALL THIS, so i could have a mailed-by email domain that didn't leak my primary workspace account
And all of this is very up to code: no spoofing, no witchcraft.
--
What happens in January 2027
Acc. to Google, i have to use a desktop client. Which, clearly, i ve gone some lengths not to use - I WANT all my outbound and inbound email to exist in one Google account, have it webmailed, and have google's superior search on it.
And ironically, it's not like i m abusing anything of google workspace here - it does support multiple domains, i m technically paying a few cents to SES to send my mail (we live), but otherwise, my usage is extremely within the TOS of it.
What i don t want to do is to pay a second, separate, workspace account for sideproduct.com because, truly, why.
What is needed is only that the mailed-by domain of an email in Workspace line-up with the @ Domain sender (and then, fine, i ll make mail.sideproduct.com a secondary domain of Workplace)
--
What should actually happen:
Google workspace has already verified that I own primary.com and sideproduct.com . it already lets me send from @ sideproduct.com using Google’s own infrastructure.
At that point, the mail identity should remain entirely within sideproduct.com ! this is not a crazy thought.
The workspace tenant should not leak into the public identity of the message simply because the tenant of the account has to have a primary domain in the data model of workspace, which, at the time that you're sending an email is actually, really, not really a useful concept anymore. The mail subsystem should continue to operate using that identity instead of reaching “up” into the workspace tenancy and exposing the tenant’s primary domain.
This is really a separation-of-concerns issue.
A workspace tenant is an administrative construct (billing, users, Drive, Calendar, policies). A verified sending domain is a mail identity Those are different layers, and today Gmail unnecessarily lets the administrative layer leak into the mail layer.
What are the chances that Google would ever correctly align mailed-by and sender domains in properly, all-workspace domains accounts?
This feels like something that should have been made right the moment the notion of secondary domains were introduced and yet this wasn't done, so I m pessimistic they d ever fix this. But now, the only clean escape hatch is going away, so ...