What SPF records are#
SPF (Sender Policy Framework) is a DNS TXT record that lists the servers allowed to send mail for a domain. Receivers check the connecting IP against that list during the SMTP transaction.
Why it matters#
Without SPF, any server can claim to send as your domain. With a broken SPF record, legitimate mail fails authentication and lands in spam. SPF is also one of the two alignment paths DMARC relies on.
How mailbox providers use it#
Gmail, Microsoft, and Yahoo combine authentication results, sender reputation, and recipient engagement into a placement decision made per message. SPF records feeds directly into that model, and weaknesses compound with other signals.
How to measure the impact#
- Baseline inbox placement with seed tests before any change.
- Make one change at a time and hold volume steady.
- Re-test after 48 to 72 hours; provider models need time to update.
- Track Postmaster Tools and SNDS alongside your seed results.
Improving it#
- Inventory every service that sends mail as your domain: your ESP, CRM, helpdesk, billing system, and internal mail server.
- Collect each vendor's SPF include mechanism (for example include:_spf.google.com) from their documentation.
- Publish one TXT record at the root of the domain starting with v=spf1, listing each include, then ending with ~all (softfail) while testing.
- Verify with a lookup tool that the record resolves and stays under 10 DNS lookups and 255 characters per string.
- Move to -all once DMARC reports confirm all legitimate sources pass.
example.com. IN TXT "v=spf1 include:_spf.google.com include:sendgrid.net ip4:203.0.113.10 -all"Frequently asked questions#
Does SPF alone stop spoofing?
No. SPF validates the envelope sender, which spoofers can set to their own domain while forging the visible From. DMARC closes that gap by requiring alignment.
What does ~all versus -all mean?
~all is softfail: receivers mark but usually accept. -all is hardfail: receivers may reject. Start with ~all, graduate to -all once DMARC data is clean.
How do I fix 'too many DNS lookups'?
Remove unused includes, replace includes with ip4/ip6 mechanisms where vendors publish static ranges, or use an SPF flattening service.