How an SPF record is built
Every SPF record is one line: it starts with v=spf1, lists who may send for your domain, and ends with what to do about everyone else. For a business on Microsoft 365 that also sends a Mailchimp newsletter, it looks like this:
v=spf1 include:spf.protection.outlook.com include:servers.mcsv.net ~all
- include: adds an email provider or service, using the name that service publishes.
- a and mx add your website's server and your own mail servers.
- ip4: and ip6: add individual servers by address.
- ~all or -all ends the record.
Three rules that break SPF when missed
- One record only. Two records starting with
v=spf1make SPF fail for everything. Edit the one you have. - At most 10 DNS lookups. Each include counts, plus the lookups inside it. The SPF checker counts them for you.
- Every sender listed. A forgotten newsletter or help-desk tool will fail SPF, and once DMARC is enforced its mail lands in spam.
After SPF: DKIM and DMARC
SPF is one of three records. Turn on DKIM in your email provider's admin panel, then publish a DMARC record with the DMARC generator. Step-by-step guides: Microsoft 365 (Office 365) and Google Workspace.
Frequently asked questions
How do I create an SPF record?
Pick your email provider, tick every other service that sends email as your domain, and choose ~all or -all. The generator builds one line starting with v=spf1. Publish it as a TXT record on your domain itself (host @) at your DNS provider.
What is the SPF record for Office 365?
For Microsoft 365 (Office 365) it is v=spf1 include:spf.protection.outlook.com -all, plus an include: for each other service that sends as you. Choose Microsoft 365 above and the generator adds the right include.
I already have an SPF record. Should I add this one too?
No. A domain must have exactly one SPF record, and two make SPF fail for every message. Replace the existing record with the generated one, and make sure everything your old record allowed is still in it.
Why is my newsletter tool not in the list?
Many services publish their own include: name in their help pages, or have you verify the domain with DKIM instead. Paste the part after include: into "Other includes". HubSpot, for example, gives every account its own include name.
What do ~all and -all mean?
~all (soft fail) flags mail from servers not on the list; -all (fail) tells receivers to refuse it. Start with ~all, and rely on DMARC to enforce it, unless you are certain the list is complete.