How to set up SPF records
SPF (Sender Policy Framework) records are DNS TXT records that specify which mail servers are authorized to send emails on behalf of your domain.
SPF Record Basics
Basic Syntax
v=spf1 [mechanisms] [modifiers] [qualifier]
Common Mechanisms
- include: Include other domain's SPF records
- ip4/ip6: Specify authorized IP addresses
- a/mx: Use domain's A or MX records
- all: Match all other cases
Qualifiers
- +: Pass (default)
- -: Fail
- ~: Soft fail
- ?: Neutral
Setup Steps
1. Identify Email Sending Sources
List all services that might send emails:
- Company mail servers
- Third-party email services (like Gmail, Outlook)
- Marketing email platforms (like Mailchimp, SendGrid)
- Automated system emails
2. Build SPF Record
Basic example:
v=spf1 include:_spf.google.com include:mailgun.org ip4:192.168.1.100 ~all
3. Common Service Provider Include Records
- Google Workspace:
include:_spf.google.com
- Microsoft 365:
include:spf.protection.outlook.com
- Mailgun:
include:mailgun.org
- SendGrid:
include:sendgrid.net
- Amazon SES:
include:amazonses.com
4. Publish to DNS
In your DNS management panel:
- Create a new TXT record
- Set name to @ or your domain name
- Set value to your complete SPF record
Best Practices
1. Avoid Common Mistakes
- Don't exceed 10 DNS lookup limit
- Only one SPF record per domain
- Avoid overly permissive rules
2. Test and Validate
Use our SPF Checker to verify:
- Syntax correctness
- DNS lookup count
- Record validity
3. Monitor and Maintain
- Regularly check SPF records
- Update SPF records when making changes
- Monitor email delivery status
Example Configurations
Small Business
v=spf1 include:_spf.google.com ~all
Medium Business
v=spf1 include:_spf.google.com include:mailgun.org include:_spf.salesforce.com ~all
Large Enterprise
v=spf1 include:_spf.google.com include:spf.protection.outlook.com ip4:203.0.113.0/24 ~all
Related Tools