What is SPF?
SPF (Sender Policy Framework) is a TXT record on your domain that lists the servers allowed to send email as you. When a message arrives claiming to be from your domain, the receiving server checks it against that list. SPF on its own only produces a pass or fail; DMARC is what tells receivers to act on a failure.
How to read an SPF record
| Part | What it means | Lookups |
|---|---|---|
v=spf1 | Marks the record as SPF. Always first. | 0 |
include:_spf.google.com | Allows everything another domain's SPF record allows. This is how email providers and services are added. | 1 + its own |
ip4:203.0.113.5 / ip6: | Allows one server or a range of addresses. | 0 |
a | Allows the server your domain points to, usually your website. | 1 |
mx | Allows the servers that receive your mail. | 1 |
~all / -all | What happens to mail from anywhere else: soft fail or fail. | 0 |
SPF records for common email providers
| Provider | SPF record |
|---|---|
| Microsoft 365 (Office 365) | v=spf1 include:spf.protection.outlook.com -all |
| Google Workspace | v=spf1 include:_spf.google.com ~all |
| Zoho Mail | v=spf1 include:zoho.com ~all |
| Proton Mail | v=spf1 include:_spf.protonmail.ch ~all |
Add an include: before the last part for every other service that sends as you. The SPF record generator builds the whole record from a list of common services.
The 10-lookup limit
Every include, a, mx, ptr, exists and redirect costs a DNS lookup, and so does every one inside each include. Receivers stop at 10. Past that SPF returns a permanent error, which fails every message and can send all your mail to spam once DMARC is enforced. The usual fix is removing includes for services you no longer use.
Frequently asked questions
What is an SPF record?
An SPF record is a TXT record on your domain that lists the servers allowed to send email as you. It starts with v=spf1, names your email provider and other senders (for example include:_spf.google.com), and ends with ~all or -all to say what happens to mail from anywhere else.
What is the SPF record for Office 365 (Microsoft 365)?
v=spf1 include:spf.protection.outlook.com -all. Add include: entries before the -all for any other service that sends as your domain, such as a newsletter tool. Publish it as a TXT record at your domain itself (host @), and keep only one SPF record.
What is the SPF record for Google Workspace?
v=spf1 include:_spf.google.com ~all. As with Microsoft 365, add an include: for every other service that sends as you, and edit the existing record instead of adding a second one.
What does "too many DNS lookups" mean?
Each include, a, mx, ptr, exists and redirect makes receivers look up more DNS records, including the lookups inside each include. SPF allows 10 in total. Above that SPF returns a permanent error and fails for every message, so remove services you no longer use or ask a sender for a flatter include.
Should I use ~all or -all?
~all (soft fail) flags mail from unlisted servers, and -all (fail) tells receivers to refuse it. With a DMARC policy of quarantine or reject they protect you equally well, so ~all is the safer default while you are still finding every service that sends as you.
Can a domain have two SPF records?
No. With more than one v=spf1 record, SPF returns a permanent error and fails for every message. Merge them into a single record. If this checker finds two, it shows you the merged version.