Free tool/Email deliverability

SPF record generator

Pick the services that send your email, add your own servers, and get one valid SPF TXT record ready to paste into your DNS. The lookup counter warns you before you hit the limit of 10.

  • Free, no signup
  • 19 email services
  • Lookup counter
  • Nothing stored

Who sends email for your domain?

Everything updates as you go.

The domain in your From address, like yourcompany.com. Used to show where the record goes.

Services that send as you

Pick every service that sends email from your domain.

0 selected

Email hosting

Transactional & marketing

CRM & support

Any other include your providers give you, such as _spf.example.com. Press Enter to add.

Single addresses or ranges, like 203.0.113.0/24.

Single addresses or ranges, like 2001:db8::/32.

Your website's server a

Allows the IP addresses in your domain's A and AAAA records. Only turn on if that server sends email. Uses 1 lookup.

Your inbound mail servers mx

Allows the servers in your MX records. Hosted providers like Google and Microsoft are already covered by their include. Uses 1 lookup.

What should happen to mail from anyone else?

~all marks mail from unlisted servers as suspicious without asking for rejection. With DMARC in place, DMARC decides what happens to it.

Your SPF record

Add it as a TXT record at your DNS host.

Type
TXT
Host
@(your root domain)

Value

v=spf1 ~all

11 characters

0 / 10 DNS lookups

None used

Counts include, a and mx at the top level. Includes can add lookups of their own, which only show up once the record is live.

Checks

  • No senders selected. This record says no server may send email for your domain. That is only right for a domain that never sends email.

  • Publish only one SPF record per domain. If a TXT record starting with v=spf1 already exists, merge its entries into this one and replace it. Two SPF records cause a PermError.

Check it after publishing

DNS changes can take a few minutes to a few hours to appear.

How it works

SPF record generator in 3 steps

  1. 1

    Pick your senders

    Tick your mailbox provider and every platform that sends as your domain. Add custom includes and IP addresses for anything else.

  2. 2

    Choose the ending

    Softfail (~all) while you test, fail (-all) once every sender is listed. The generator explains what each one does.

  3. 3

    Publish one TXT record

    Copy the value into a single TXT record on your root domain, then check it with our SPF, DKIM and DMARC checker.

What you get

Everything a correct SPF record needs

Built to RFC 7208, so the record you copy is the record receivers expect.

Official includes

Each service shows the include from its own setup documentation, plus a note when it authenticates another way, like SendGrid's automated security or Resend's sending subdomain.

DNS lookup counter

Counts every include, a and mx toward the limit of 10 and warns before the record would fail with a PermError.

Strict IP validation

IPv4 ranges from /0 to /32 and IPv6 ranges from /0 to /128 are checked properly. Invalid entries are flagged and left out.

Duplicate cleanup

Repeated includes and addresses are removed automatically, so nothing wastes a lookup.

Length check

Records over 255 characters are flagged, with the split-string version ready if your DNS host needs it.

One-record reminder

Clear guidance on merging with an existing SPF record, because two v=spf1 records break SPF.

Guide

How to set up SPF correctly

SPF (Sender Policy Framework) is a TXT record that lists the servers allowed to send email for your domain. Receivers compare the server that delivered a message with that list. Without SPF, and without DKIM and DMARC alongside it, mailbox providers have little reason to trust mail from your domain, and since 2024 Gmail and Yahoo require SPF or DKIM from every sender, and SPF, DKIM and DMARC from bulk senders.

1. Make a list of everything that sends as you

Start with your mailbox provider, such as Google Workspace or Microsoft 365. Then add every platform that sends from your domain: your product's transactional email, your newsletter tool, your help desk, your CRM and your billing system. Missing one is the most common reason legitimate mail fails.

Some services don't need an include on your root domain at all. They send from their own bounce domain or from a subdomain you point at them, and authenticate your domain with DKIM. The generator notes these cases, but always follow the records your provider's dashboard shows.

2. Publish exactly one SPF record

A domain may have only one TXT record starting with v=spf1. If one exists already, add the new entries to it rather than creating another. Two SPF records produce a PermError and SPF fails for all your mail.

To publish, open your DNS host (often your registrar or a service such as Cloudflare), create a TXT record, set the host to @ for the root domain (some hosts want the domain name or an empty field), and paste the value. The TTL can stay at your host's default. Changes usually appear within minutes, though they can take longer.

3. Stay under 10 DNS lookups

RFC 7208 caps SPF at 10 DNS-querying mechanisms: include, a, mx, ptr, exists and redirect. Lookups inside each include count too, so one include can use several. ip4, ip6 and all are free.

  • Remove what you no longer use. Old tools often stay in SPF long after you cancel them.
  • Drop a and mx unless those servers send mail. Hosted mailbox providers are already covered by their include.
  • Move senders to subdomains. A marketing platform on news.yourdomain.com gets its own SPF record and its own 10 lookups.
  • Flatten with care. Replacing includes with the IP addresses they resolve to cuts lookups, but providers change their IPs without notice. A flattened record needs to be kept up to date, by hand or with a service that does it for you.

4. Choose the ending

EndingMeaningWhen to use it
~allSoftfail: unlisted servers are suspiciousWhile you confirm every sender is listed
-allFail: unlisted servers aren't allowedOnce reports show all legitimate mail passing
?allNeutral: no statementRarely; it gives no protection

5. Add DKIM and DMARC

SPF checks the envelope sender, which people never see, and it breaks when mail is forwarded. DKIM signs each message, and DMARC checks that SPF or DKIM passes for the domain in the visible From address. Create your policy with the DMARC record generator, then confirm all three with the SPF, DKIM and DMARC checker.

FAQ

Frequently asked questions

Can't find your answer? Read the Atlis docs.

How do I create an SPF record?

List every service that sends email from your domain, such as your mailbox provider and your email platforms, and add each one's include. Add any of your own server IP addresses, choose how strict the ending should be (~all or -all), then publish the result as a single TXT record on your root domain. The generator above builds the value for you as you pick.

Where do I add the SPF record?

At the DNS host for your domain, which is often your registrar or a service like Cloudflare. Create a TXT record with the host or name set to @ (some DNS hosts want the domain itself, or leave the field blank) and paste the value that starts with v=spf1.

Can I have two SPF records?

No. A domain must have exactly one TXT record that starts with v=spf1. With two, receivers return a PermError and SPF fails. If you already have one, merge the new includes into it instead of adding a second record.

What is the SPF 10 DNS lookup limit?

RFC 7208 limits SPF evaluation to 10 mechanisms that need a DNS query: include, a, mx, ptr, exists and the redirect modifier. Includes count their own nested lookups too. Past 10, the result is a PermError, which receivers treat as an SPF failure. ip4, ip6 and all don't count.

Should I use ~all or -all?

Use ~all (softfail) while you're confirming every sender is listed. Once your DMARC reports show all legitimate mail passing, you can move to -all (fail). With DMARC enforced, DMARC's policy decides what happens to failing mail either way, so many domains keep ~all.

What does include:_spf.google.com mean?

It tells receivers to also accept any server listed in Google's own SPF record, _spf.google.com. That's how Google Workspace authorises its sending servers for your domain without you listing their IP addresses.

Is SPF enough to stop spoofing?

No. SPF checks the hidden envelope sender (Return-Path), not the From address people see. DMARC ties SPF and DKIM to the visible From domain and tells receivers what to do when they fail, so you need SPF, DKIM and DMARC together.

My SPF record is longer than 255 characters. Is that a problem?

Not by itself. A single DNS TXT string holds up to 255 characters, so a longer record is stored as several quoted strings in one TXT record, which receivers join back together. Most DNS hosts split long values automatically.

Atlis

Authenticated email. Now make it worth opening.

Atlis tracks what each user does after signup and sends lifecycle emails automatically: onboarding nudges, re-engagement, churn recovery and failed-payment recovery.

Start free

Free plan · No credit card · 10-minute setup