Founder price · 100 spots leftReserve

[ Free tool ]

SPF record generator

Build a valid SPF record for your domain: pick Google Workspace, Microsoft 365 and other senders, count DNS lookups, and copy one TXT record.

· 5 min read

[ In short ]

  • An SPF record is one TXT record at your domain that lists the servers allowed to send its mail, like v=spf1 include:_spf.google.com ~all.
  • A domain has exactly one SPF record, and checking it may take at most 10 DNS lookups; past either limit, SPF fails.
  • Newsletter and transactional services often authenticate on their own bounce domain and do not belong in your record.
  • Start with ~all, and move to -all once DMARC reports show every real sender passing.

01Build your SPF record

Tick every service that sends email as your domain, add your own servers if you have any, and choose what receivers should do with mail from anywhere else. The record updates as you go, with the number of DNS lookups it costs and anything that would break it.

Who sends email as your domain
Your own servers and other services

Separate several with commas or spaces.

Mail from anywhere else

Your SPF record

DNS lookups: 1 / 10

TXT record at your domain (@)
Type
TXT
Host
@
Value
v=spf1 include:_spf.google.com ~all

A domain has one SPF record. If it already has one (a TXT value starting with v=spf1), replace it with this one; two records make SPF fail.

Checks

  • Note: With ~all, mail from other servers is marked, not refused. Move to -all once DMARC reports show every sender passes.

Runs in your browser. Nothing you type is sent anywhere.

The includes come from each provider’s own setup guide; nested lookups were measured on the date at the top of this page.

02What an SPF record does

SPF (Sender Policy Framework, RFC 7208) lets a receiving server ask your domain: is this server allowed to send mail for you? The answer lives in a TXT record at the domain itself. The receiver checks the domain in the envelope sender (the Return-Path, where bounces go), not the From address people see.

That detail matters. SPF on its own does not stop someone from putting your address in the From line. DMARC closes that gap by requiring SPF or DKIM to pass for a domain that matches the From address. If you are new to the three, read SPF, DKIM and DMARC explained first.

Example record
v=spf1 ip4:203.0.113.10 include:_spf.google.com ~all
PartMeaningDNS lookups
v=spf1Marks the TXT record as SPF. Always first.0
ip4: / ip6:An address or range allowed to send.0
a / mxThe servers your domain’s A or MX records point to.1 each
include:Everything another domain’s SPF record allows (your provider’s).1, plus its own
~allAnything else: softfail, accept but mark as suspicious.0
-allAnything else: fail, the receiver may refuse it.0

03The 10-lookup limit, and why records break

Checking an SPF record may cause at most 10 DNS lookups for include, a, mx, ptr, exists and redirect (RFC 7208 §4.6.4). Addresses cost nothing. Each include costs one, plus every include nested inside the provider’s own record. Go over and the receiver returns permerror: SPF fails for all your mail, not just the last service you added.

The generator counts the nested lookups of the providers it knows, as their records stood when this page was checked. For any other include it counts one and tells you the total may be higher. Providers change their records without notice, so check the final count with a DNS lookup tool now and then.

When you run out of lookups

  • Move bulk or marketing mail to a subdomain (news.example.com). Each subdomain has its own record and its own budget of 10.
  • Drop includes for services that authenticate on their own bounce domain (see below).
  • Replace an include with the provider’s published ip4 and ip6 ranges, only if they document stable ones. You then have to watch them for changes.
  • Remove services you no longer use. Old includes are the most common cause.

04Services with their own SPF rules

SPF checks the Return-Path domain. Many sending services use their own Return-Path, or one on a subdomain of yours that they manage, so adding them to your root record spends a lookup for nothing.

ServiceWhat to do
Zoho MailAccounts in another Zoho data centre: use the include your Zoho admin console shows.
SendGridOnly with Automated Security off. With it on, SendGrid publishes SPF on its own em subdomain through a CNAME.
Amazon SESNot on your root domain. With a custom MAIL FROM subdomain, that subdomain gets its own "v=spf1 include:amazonses.com ~all".
ResendNot on your root domain. Resend asks for an SPF record on its own "send" subdomain; copy it from your Resend dashboard.
PostmarkNot needed. Postmark passes SPF on its own Return-Path domain; add its custom Return-Path CNAME for alignment.
Mailchimp / MandrillNot needed for campaigns: the bounce address is Mailchimp’s own domain. Set up its DKIM records instead.
HubSpotHubSpot gives each account its own include (like 123456.spf03.hubspotemail.net). Paste it under "Other includes".

05How to publish it

  1. Look for an existing TXT record at your domain (host @) that starts with v=spf1.
  2. If there is one, edit it and replace its value with the generated record. Never add a second SPF record: two records make SPF fail with permerror.
  3. If the record is longer than 255 characters, paste the quoted, split form if your DNS panel asks for it. Receivers join the strings back together.
  4. Wait for the TTL to pass, then send a message to a Gmail account and check "Show original": SPF should say PASS.
  5. Publish a DMARC record with reports, so you can see every server that sends as you before tightening anything.

Not sure which records your domain needs in total? The MX records guide and the deliverability checklist list them all.

06Common SPF mistakes

  • Two SPF records on the same domain, one per provider. Merge them into one.
  • Using ptr. It is deprecated, slow, and receivers may ignore it (RFC 7208 §5.5).
  • Ending with +all or ?all, which authorizes anyone or says nothing.
  • A trailing dot or a space after include: (include: _spf.google.com). Both break the record.
  • Forgetting a sender: the billing tool, the helpdesk or the website’s contact form. DMARC reports show them.
  • Adding mx out of habit. It only belongs there if your incoming servers also send.

If you host mail with Skein, the app writes these records for you on supported DNS providers. The demo shows the rest of the product with sample data.

Questions

Should I use ~all or -all?
Google recommends ~all and Microsoft recommends -all. Both count as SPF failures for DMARC. Start with ~all while you find every sender, then move to -all once DMARC reports are clean, if you want the stricter signal.
Can I have two SPF records?
No. A domain must have at most one SPF record (RFC 7208 §3.2). Two records make receivers return permerror and SPF fails. Merge every include into a single record.
What happens if my SPF record has more than 10 DNS lookups?
Receivers stop evaluating and return permerror, which counts as a failure for all your mail. Move some senders to a subdomain, remove unused includes, or replace an include with documented IP ranges.
Does SPF stop people from spoofing my From address?
Not on its own. SPF checks the envelope sender, which can differ from the visible From address. A DMARC policy requires SPF or DKIM to pass for the From domain, which is what stops exact-domain spoofing.
Is my data sent anywhere when I use this generator?
No. The record is built in your browser and nothing you type leaves the page.

See Skein follow up for you

Business email on your own domain with an agent that follows up on every conversation. Hosted in the EU. Try the demo with sample mail, nothing to install.

[ Sources ]

  1. 01RFC 7208: Sender Policy Framework (SPF)
  2. 02Google Workspace: Set up SPF
  3. 03Microsoft: Set up SPF for your Microsoft 365 domain
  4. 04Zoho Mail: SPF configuration
  5. 05Fastmail: manual DNS configuration
  6. 06Proton: Anti-spoofing for custom domains
  7. 07Amazon SES: Using a custom MAIL FROM domain
  8. 08Resend: AWS Route 53 setup
  9. 09Postmark: Why we no longer ask for SPF records
  10. 10Mailchimp Transactional: Authentication and delivery
  11. 11SendGrid: Automated Security and domain authentication
  12. 12HubSpot: Manage email authentication

Facts about other products were checked on 5 Oct 2026; prices and plans change.

[ Read next ]