SPF Record Generator
Tick the services that send email for your domain, add any IP addresses, and copy a ready-to-publish SPF record.
How it works
An SPF record is a single line of text, published as a TXT record, that lists who may send email for your domain. This generator assembles one from your choices, in the order receivers expect: first v=spf1, then the senders, and last the all term that says what to do with everyone else.
It checks each IP and domain you type, counts the DNS lookups the terms need against the limit of 10, and warns when the record is too long for one DNS string. Include names for the listed services are the ones their documentation published at the time of writing, so confirm against your provider's current instructions before publishing.
| Part | Use it for |
|---|---|
include:domain | An email service that sends on your behalf. |
ip4: / ip6: | Your own server addresses or ranges. |
mx, a | The servers your domain's MX or address records point to. |
~all / -all | What to do with mail from anywhere else. |
After publishing, verify it with the SPF Record Checker, which follows every include and counts the real lookups.
Frequently asked
Where do I publish the SPF record?
As a TXT record on your domain's root (the host is "@" or blank), in the DNS panel of whoever hosts your DNS. Do not create a second SPF record: if one exists, replace it with the merged one.
Should I use ~all or -all?
~all (softfail) is the safe default, and works well with DMARC. Move to -all once you are certain every legitimate sender is listed.
Why is there a limit of 10 DNS lookups?
To stop receivers doing unlimited work. Each include, a, mx, ptr, exists and redirect counts, including those nested inside included records. Over 10 and SPF fails with a permanent error.
Do I need SPF if I use Google Workspace or Microsoft 365?
Yes. They give you the include to add, and without an SPF record receivers cannot confirm their servers may send for you.
Why does my record need splitting?
A single DNS string is limited to 255 characters. Longer records must be stored as several quoted strings in one TXT record, which most DNS panels do for you.