What is SPF?
SPF (Sender Policy Framework) is a DNS TXT record that lists which servers may send mail for a domain. A receiver checks the connecting server's IP address against that list.
What SPF checks
SPF checks the envelope sender (also called the return path or MAIL FROM), not the visible From address. For DMARC, the SPF result only counts if the envelope sender domain aligns with the From domain. See What is DMARC? for alignment.
Anatomy of a record
v=spf1 include:_spf.example.net ip4:203.0.113.10 mx -all| Part | Meaning |
|---|---|
v=spf1 |
Version, must come first |
include: |
Also allow whatever another domain's SPF record allows |
ip4: / ip6: |
Allow a specific address or range |
a / mx |
Allow the domain's A or MX hosts |
-all |
Fail everything else (hard fail) |
~all |
Soft fail everything else |
?all |
Neutral, no statement |
Tip: while you are still discovering senders, ~all is safer than -all. Move to -all after the reports show every legitimate sender is listed.
Rules that cause silent failures
| Rule | Consequence |
|---|---|
| Only one SPF record per domain | Two records cause a permanent error, and SPF fails |
At most 10 DNS lookups (each include, a, mx, ptr and redirect counts, and nested lookups count too) |
Over 10 causes a permanent error |
| Record must be valid text | Typos such as a missing space or colon break the record |
Note: the SPF Lookup tool in DMARC+ counts lookups for you and warns when you reach 10. See Lookup tools.
Reducing lookups
- Remove includes for services you no longer use.
- Replace an include with explicit
ip4:ranges when the sender's addresses are stable. - Use SPF flattening, where the included addresses are resolved into a list. DMARC+ offers a managed SPF record for this purpose. See Managed record tools.
SPF and forwarding
SPF breaks when a message is forwarded, because the forwarding server's IP is not in your record. DKIM usually survives forwarding, which is why DMARC only needs one of the two to pass and aligned. See Troubleshooting.
Checking your SPF
- Open DMARC+ > Tools > SPF.
- Select a domain.
- Read the Summary tab for the lookup count and the SPF Record tab for the record and include tree.
Next steps
- Managed record tools to generate a record.
- Managing third-party senders to add services safely.