DnsGuard › Guides › SPF

SPF records explained

SPF (Sender Policy Framework, RFC 7208) is a DNS TXT record that lists which servers are allowed to send email for your domain. A receiving server looks up the SPF record of the domain in the message's envelope sender (the Return-Path / MAIL FROM address) and checks whether the connecting server's IP address is on the list.

What an SPF record looks like

It's a single TXT record on the domain itself (not a subdomain) that starts with v=spf1:

example.com.  TXT  "v=spf1 include:_spf.google.com include:sendgrid.net ip4:203.0.113.10 -all"

Receivers read it left to right and stop at the first mechanism that matches:

MechanismMatches when the sending IP…DNS lookups
ip4: / ip6:is in the given address or range0
ais an A/AAAA address of the domain1
mxis one of the domain's mail servers1 (plus the MX hosts' addresses)
include:passes the other domain's SPF record (how you authorize Google Workspace, Microsoft 365, SendGrid, etc.)1 + whatever that record uses
exists:makes the given name resolve (advanced)1
ptrreverse-resolves to the domain (deprecated; don't use it)1+
allalways matches; it goes last and sets the default result0

A redirect= modifier replaces the whole policy with another domain's record and also costs a lookup.

~all vs -all vs ?all

Each mechanism can have a qualifier. The one on all decides what happens to mail from servers you didn't list:

The 10-lookup limit

Evaluating SPF may trigger at most 10 DNS lookups in total, counting every include, a, mx, ptr, exists and redirect, including the ones inside included records. Go over and the result is permerror, which most receivers treat as a fail. Each SaaS tool you add with another include: brings you closer. To get back under the limit, remove services you no longer use, replace a/mx with ip4: ranges where they're stable, or send bulk mail from a subdomain with its own SPF record.

Common SPF mistakes

How DnsGuard scores SPF (25 of 100 points)

10 points for a single valid record; up to 10 more for the default qualifier (-all 10, ~all or redirect 8, ?all or no all 2, +all 0); and 5 more if it stays within 10 lookups. A record that returns permerror is capped at 5 points, and +all scores 0.

Check your domain now

Free check of SPF, DKIM, DMARC, BIMI, MX, MTA-STS and TLS-RPT with a 0–100 score and plain-English fixes. No sign-up.

More guides: DKIM · DMARC · BIMI · MTA-STS & TLS-RPT