Daily Website Report
Free tool

SPF Record Generator

Build one correct SPF record for Microsoft 365 (Office 365), Google Workspace or any other email provider. Tick the services that send email as you, copy the record, and publish it as a TXT record. Free, no signup.

Other services that send email as you Newsletters, help desks, shops, invoicing. Tick every one you use.

Your SPF record

Add this as a TXT record at your DNS provider (where you manage your domain, such as Cloudflare, GoDaddy, Namecheap or your web host).

Type: TXT · Name/Host: @
v=spf1 include:_spf.google.com ~all
  • ~all (soft fail) is the safe choice: if a sender is missing from the list, its mail is flagged rather than refused. With an enforced DMARC policy it protects you just as well.
  • Uses 1 DNS lookup at the top level. Each include can use more inside it, and the limit is 10 in total. After publishing, run the SPF checker to see the exact count.
  • Does your website's contact form send email as your domain? If so, tick "My website sends email" or route it through one of the services above.
  • A domain must have exactly one SPF record. If you already have one starting with v=spf1, replace it with this one instead of adding a second.

Published it? Check that it worked

DNS changes usually show up within minutes. The SPF checker shows the exact lookup count, including the lookups inside each include.

Check my SPF record → Next: a DMARC record

How an SPF record is built

Every SPF record is one line: it starts with v=spf1, lists who may send for your domain, and ends with what to do about everyone else. For a business on Microsoft 365 that also sends a Mailchimp newsletter, it looks like this:

v=spf1 include:spf.protection.outlook.com include:servers.mcsv.net ~all

  • include: adds an email provider or service, using the name that service publishes.
  • a and mx add your website's server and your own mail servers.
  • ip4: and ip6: add individual servers by address.
  • ~all or -all ends the record.

Three rules that break SPF when missed

  1. One record only. Two records starting with v=spf1 make SPF fail for everything. Edit the one you have.
  2. At most 10 DNS lookups. Each include counts, plus the lookups inside it. The SPF checker counts them for you.
  3. Every sender listed. A forgotten newsletter or help-desk tool will fail SPF, and once DMARC is enforced its mail lands in spam.

After SPF: DKIM and DMARC

SPF is one of three records. Turn on DKIM in your email provider's admin panel, then publish a DMARC record with the DMARC generator. Step-by-step guides: Microsoft 365 (Office 365) and Google Workspace.

Frequently asked questions

How do I create an SPF record?

Pick your email provider, tick every other service that sends email as your domain, and choose ~all or -all. The generator builds one line starting with v=spf1. Publish it as a TXT record on your domain itself (host @) at your DNS provider.

What is the SPF record for Office 365?

For Microsoft 365 (Office 365) it is v=spf1 include:spf.protection.outlook.com -all, plus an include: for each other service that sends as you. Choose Microsoft 365 above and the generator adds the right include.

I already have an SPF record. Should I add this one too?

No. A domain must have exactly one SPF record, and two make SPF fail for every message. Replace the existing record with the generated one, and make sure everything your old record allowed is still in it.

Why is my newsletter tool not in the list?

Many services publish their own include: name in their help pages, or have you verify the domain with DKIM instead. Paste the part after include: into "Other includes". HubSpot, for example, gives every account its own include name.

What do ~all and -all mean?

~all (soft fail) flags mail from servers not on the list; -all (fail) tells receivers to refuse it. Start with ~all, and rely on DMARC to enforce it, unless you are certain the list is complete.