An SPF record is a DNS TXT record that lists which servers are allowed to send email for your domain, and it is one of the fastest ways to cut down on spoofing. If your messages land in spam or someone forges your address, a correct SPF record is usually the first fix. Here is how it works and how to build one.
What an SPF record actually is
SPF stands for Sender Policy Framework. It lives as a single DNS TXT record on your domain and always starts with v=spf1. After that prefix you list the senders you authorize using mechanisms:
- include: pulls in another domain’s SPF rules, like
include:_spf.google.comfor Google Workspace. - a and mx authorize the servers in your domain’s A and MX records.
- ip4: and ip6: authorize specific addresses or ranges, like
ip4:198.51.100.0/24.
The record ends with an “all” mechanism that decides what happens to everything else. Use ~all for softfail, which flags unlisted senders but still delivers, or -all for hard fail, which tells receivers to reject them outright.
Rules that trip people up
Two limits cause most SPF problems. First, you can have only one SPF record per domain. Publishing two TXT records starting with v=spf1 makes the whole thing invalid, so every sender has to be merged into one line. Second, SPF allows a maximum of 10 DNS lookups when a receiver evaluates your record. Each include, a, and mx counts toward that limit, and going over it causes a permerror that breaks validation. Keep your includes lean.
SPF is also only one layer. It pairs with DKIM, which signs your messages, and DMARC, which tells receivers what to do when SPF or DKIM fail and where to send reports. All three together give you real protection.
Generate your SPF record
The SPF Record Generator builds a valid record for you without guesswork:
- Open the SPF Record Generator.
- Select your mail providers, such as Google Workspace or Microsoft 365, to add the right
includemechanisms. - Add any extra sending IPs or ranges with
ip4:andip6:. - Choose your policy,
~allwhile testing or-allonce you trust the list. - Copy the generated TXT record and publish it in your DNS as a single SPF entry.
Everything runs in your browser with no server-side requests, so your domain details never leave your device.
Related tools
- DMARC Record Generator: add the policy layer that acts on SPF and DKIM results.
- Email Header Analyzer: inspect a real message to confirm SPF passed.
- Security Headers Generator: harden the web side of your domain too.
Build one clean record, keep it under 10 lookups, end it with -all, and you have shut the door on most spoofers.