EML

SPF Record Generator

Tick the services that send email for your domain, add any IP addresses, and copy a ready-to-publish SPF record.

WHICH SERVICES SEND YOUR EMAIL?
YOUR SPF RECORD

            

How it works

An SPF record is a single line of text, published as a TXT record, that lists who may send email for your domain. This generator assembles one from your choices, in the order receivers expect: first v=spf1, then the senders, and last the all term that says what to do with everyone else.

It checks each IP and domain you type, counts the DNS lookups the terms need against the limit of 10, and warns when the record is too long for one DNS string. Include names for the listed services are the ones their documentation published at the time of writing, so confirm against your provider's current instructions before publishing.

PartUse it for
include:domainAn email service that sends on your behalf.
ip4: / ip6:Your own server addresses or ranges.
mx, aThe servers your domain's MX or address records point to.
~all / -allWhat to do with mail from anywhere else.

After publishing, verify it with the SPF Record Checker, which follows every include and counts the real lookups.

Frequently asked

Where do I publish the SPF record?

As a TXT record on your domain's root (the host is "@" or blank), in the DNS panel of whoever hosts your DNS. Do not create a second SPF record: if one exists, replace it with the merged one.

Should I use ~all or -all?

~all (softfail) is the safe default, and works well with DMARC. Move to -all once you are certain every legitimate sender is listed.

Why is there a limit of 10 DNS lookups?

To stop receivers doing unlimited work. Each include, a, mx, ptr, exists and redirect counts, including those nested inside included records. Over 10 and SPF fails with a permanent error.

Do I need SPF if I use Google Workspace or Microsoft 365?

Yes. They give you the include to add, and without an SPF record receivers cannot confirm their servers may send for you.

Why does my record need splitting?

A single DNS string is limited to 255 characters. Longer records must be stored as several quoted strings in one TXT record, which most DNS panels do for you.