Dmarc Overview

What is SPF?

SPF (Sender Policy Framework) is a DNS TXT record that lists which servers may send mail for a domain. A receiver checks the connecting server's IP address against that list.

What SPF checks

SPF checks the envelope sender (also called the return path or MAIL FROM), not the visible From address. For DMARC, the SPF result only counts if the envelope sender domain aligns with the From domain. See What is DMARC? for alignment.

Anatomy of a record

v=spf1 include:_spf.example.net ip4:203.0.113.10 mx -all
Part Meaning
v=spf1 Version, must come first
include: Also allow whatever another domain's SPF record allows
ip4: / ip6: Allow a specific address or range
a / mx Allow the domain's A or MX hosts
-all Fail everything else (hard fail)
~all Soft fail everything else
?all Neutral, no statement

Tip: while you are still discovering senders, ~all is safer than -all. Move to -all after the reports show every legitimate sender is listed.

Rules that cause silent failures

Rule Consequence
Only one SPF record per domain Two records cause a permanent error, and SPF fails
At most 10 DNS lookups (each include, a, mx, ptr and redirect counts, and nested lookups count too) Over 10 causes a permanent error
Record must be valid text Typos such as a missing space or colon break the record

Note: the SPF Lookup tool in DMARC+ counts lookups for you and warns when you reach 10. See Lookup tools.

Reducing lookups

  • Remove includes for services you no longer use.
  • Replace an include with explicit ip4: ranges when the sender's addresses are stable.
  • Use SPF flattening, where the included addresses are resolved into a list. DMARC+ offers a managed SPF record for this purpose. See Managed record tools.

SPF and forwarding

SPF breaks when a message is forwarded, because the forwarding server's IP is not in your record. DKIM usually survives forwarding, which is why DMARC only needs one of the two to pass and aligned. See Troubleshooting.

Checking your SPF

  1. Open DMARC+ > Tools > SPF.
  2. Select a domain.
  3. Read the Summary tab for the lookup count and the SPF Record tab for the record and include tree.

Next steps