SPF records explained
SPF (Sender Policy Framework, RFC 7208) is a DNS TXT record that lists which servers are allowed to send email for your domain. A receiving server looks up the SPF record of the domain in the message's envelope sender (the Return-Path / MAIL FROM address) and checks whether the connecting server's IP address is on the list.
What an SPF record looks like
It's a single TXT record on the domain itself (not a subdomain) that starts with v=spf1:
example.com. TXT "v=spf1 include:_spf.google.com include:sendgrid.net ip4:203.0.113.10 -all"
Receivers read it left to right and stop at the first mechanism that matches:
| Mechanism | Matches when the sending IP… | DNS lookups |
|---|---|---|
ip4: / ip6: | is in the given address or range | 0 |
a | is an A/AAAA address of the domain | 1 |
mx | is one of the domain's mail servers | 1 (plus the MX hosts' addresses) |
include: | passes the other domain's SPF record (how you authorize Google Workspace, Microsoft 365, SendGrid, etc.) | 1 + whatever that record uses |
exists: | makes the given name resolve (advanced) | 1 |
ptr | reverse-resolves to the domain (deprecated; don't use it) | 1+ |
all | always matches; it goes last and sets the default result | 0 |
A redirect= modifier replaces the whole policy with another domain's record and also costs a lookup.
~all vs -all vs ?all
Each mechanism can have a qualifier. The one on all decides what happens to mail from servers you didn't list:
-all(fail): unlisted servers are not allowed. The strictest setting, and the right one once your list is complete.~all(softfail): unlisted servers are suspicious. Common and reasonable while you're still finding every sender; with DMARC at enforcement, softfail and fail are treated much the same.?all(neutral): no opinion. It gives almost no protection.+all(pass): anyone may send as you. Never use it.
The 10-lookup limit
Evaluating SPF may trigger at most 10 DNS lookups in total, counting every include, a, mx, ptr, exists and redirect, including the ones inside included records. Go over and the result is permerror, which most receivers treat as a fail. Each SaaS tool you add with another include: brings you closer. To get back under the limit, remove services you no longer use, replace a/mx with ip4: ranges where they're stable, or send bulk mail from a subdomain with its own SPF record.
Common SPF mistakes
- Two SPF records. A domain must publish exactly one TXT record starting with
v=spf1. Two records is a permerror. Merge them into one. - Too many lookups (see above).
- A missing sender. Your newsletter tool, CRM or helpdesk sends as your domain but isn't in the record.
- Typos like
include: _spf.google.com(with a space) orv=spf1missing at the start. - Relying on SPF alone. SPF breaks when mail is forwarded and only checks the envelope sender, not the From address people see. Pair it with DKIM and DMARC.
How DnsGuard scores SPF (25 of 100 points)
10 points for a single valid record; up to 10 more for the default qualifier (-all 10, ~all or redirect 8, ?all or no all 2, +all 0); and 5 more if it stays within 10 lookups. A record that returns permerror is capped at 5 points, and +all scores 0.
Check your domain now
Free check of SPF, DKIM, DMARC, BIMI, MX, MTA-STS and TLS-RPT with a 0–100 score and plain-English fixes. No sign-up.
More guides: DKIM · DMARC · BIMI · MTA-STS & TLS-RPT