SPF record generator
Pick the services that send your email, add your own servers, and get one valid SPF TXT record ready to paste into your DNS. The lookup counter warns you before you hit the limit of 10.
- Free, no signup
- 19 email services
- Lookup counter
- Nothing stored
Who sends email for your domain?
Everything updates as you go.
The domain in your From address, like yourcompany.com. Used to show where the record goes.
Services that send as you
Pick every service that sends email from your domain.
Email hosting
Transactional & marketing
CRM & support
Any other include your providers give you, such as _spf.example.com. Press Enter to add.
Single addresses or ranges, like 203.0.113.0/24.
Single addresses or ranges, like 2001:db8::/32.
Your website's server a
Allows the IP addresses in your domain's A and AAAA records. Only turn on if that server sends email. Uses 1 lookup.
Your inbound mail servers mx
Allows the servers in your MX records. Hosted providers like Google and Microsoft are already covered by their include. Uses 1 lookup.
What should happen to mail from anyone else?
~all marks mail from unlisted servers as suspicious without asking for rejection. With DMARC in place, DMARC decides what happens to it.
Your SPF record
Add it as a TXT record at your DNS host.
- Type
- TXT
- Host
- @(your root domain)
Value
v=spf1 ~all
11 characters
0 / 10 DNS lookups
None used
Counts include, a and mx at the top level. Includes can add lookups of their own, which only show up once the record is live.
Checks
No senders selected. This record says no server may send email for your domain. That is only right for a domain that never sends email.
Publish only one SPF record per domain. If a TXT record starting with v=spf1 already exists, merge its entries into this one and replace it. Two SPF records cause a PermError.
DNS changes can take a few minutes to a few hours to appear.
SPF record generator in 3 steps
- 1
Pick your senders
Tick your mailbox provider and every platform that sends as your domain. Add custom includes and IP addresses for anything else.
- 2
Choose the ending
Softfail (~all) while you test, fail (-all) once every sender is listed. The generator explains what each one does.
- 3
Publish one TXT record
Copy the value into a single TXT record on your root domain, then check it with our SPF, DKIM and DMARC checker.
Everything a correct SPF record needs
Built to RFC 7208, so the record you copy is the record receivers expect.
Official includes
Each service shows the include from its own setup documentation, plus a note when it authenticates another way, like SendGrid's automated security or Resend's sending subdomain.
DNS lookup counter
Counts every include, a and mx toward the limit of 10 and warns before the record would fail with a PermError.
Strict IP validation
IPv4 ranges from /0 to /32 and IPv6 ranges from /0 to /128 are checked properly. Invalid entries are flagged and left out.
Duplicate cleanup
Repeated includes and addresses are removed automatically, so nothing wastes a lookup.
Length check
Records over 255 characters are flagged, with the split-string version ready if your DNS host needs it.
One-record reminder
Clear guidance on merging with an existing SPF record, because two v=spf1 records break SPF.
How to set up SPF correctly
SPF (Sender Policy Framework) is a TXT record that lists the servers allowed to send email for your domain. Receivers compare the server that delivered a message with that list. Without SPF, and without DKIM and DMARC alongside it, mailbox providers have little reason to trust mail from your domain, and since 2024 Gmail and Yahoo require SPF or DKIM from every sender, and SPF, DKIM and DMARC from bulk senders.
1. Make a list of everything that sends as you
Start with your mailbox provider, such as Google Workspace or Microsoft 365. Then add every platform that sends from your domain: your product's transactional email, your newsletter tool, your help desk, your CRM and your billing system. Missing one is the most common reason legitimate mail fails.
Some services don't need an include on your root domain at all. They send from their own bounce domain or from a subdomain you point at them, and authenticate your domain with DKIM. The generator notes these cases, but always follow the records your provider's dashboard shows.
2. Publish exactly one SPF record
A domain may have only one TXT record starting with v=spf1. If one exists already, add the new entries to it rather than creating another. Two SPF records produce a PermError and SPF fails for all your mail.
To publish, open your DNS host (often your registrar or a service such as Cloudflare), create a TXT record, set the host to @ for the root domain (some hosts want the domain name or an empty field), and paste the value. The TTL can stay at your host's default. Changes usually appear within minutes, though they can take longer.
3. Stay under 10 DNS lookups
RFC 7208 caps SPF at 10 DNS-querying mechanisms: include, a, mx, ptr, exists and redirect. Lookups inside each include count too, so one include can use several. ip4, ip6 and all are free.
- Remove what you no longer use. Old tools often stay in SPF long after you cancel them.
- Drop a and mx unless those servers send mail. Hosted mailbox providers are already covered by their include.
- Move senders to subdomains. A marketing platform on
news.yourdomain.comgets its own SPF record and its own 10 lookups. - Flatten with care. Replacing includes with the IP addresses they resolve to cuts lookups, but providers change their IPs without notice. A flattened record needs to be kept up to date, by hand or with a service that does it for you.
4. Choose the ending
| Ending | Meaning | When to use it |
|---|---|---|
~all | Softfail: unlisted servers are suspicious | While you confirm every sender is listed |
-all | Fail: unlisted servers aren't allowed | Once reports show all legitimate mail passing |
?all | Neutral: no statement | Rarely; it gives no protection |
5. Add DKIM and DMARC
SPF checks the envelope sender, which people never see, and it breaks when mail is forwarded. DKIM signs each message, and DMARC checks that SPF or DKIM passes for the domain in the visible From address. Create your policy with the DMARC record generator, then confirm all three with the SPF, DKIM and DMARC checker.
How do I create an SPF record?
List every service that sends email from your domain, such as your mailbox provider and your email platforms, and add each one's include. Add any of your own server IP addresses, choose how strict the ending should be (~all or -all), then publish the result as a single TXT record on your root domain. The generator above builds the value for you as you pick.
Where do I add the SPF record?
At the DNS host for your domain, which is often your registrar or a service like Cloudflare. Create a TXT record with the host or name set to @ (some DNS hosts want the domain itself, or leave the field blank) and paste the value that starts with v=spf1.
Can I have two SPF records?
No. A domain must have exactly one TXT record that starts with v=spf1. With two, receivers return a PermError and SPF fails. If you already have one, merge the new includes into it instead of adding a second record.
What is the SPF 10 DNS lookup limit?
RFC 7208 limits SPF evaluation to 10 mechanisms that need a DNS query: include, a, mx, ptr, exists and the redirect modifier. Includes count their own nested lookups too. Past 10, the result is a PermError, which receivers treat as an SPF failure. ip4, ip6 and all don't count.
Should I use ~all or -all?
Use ~all (softfail) while you're confirming every sender is listed. Once your DMARC reports show all legitimate mail passing, you can move to -all (fail). With DMARC enforced, DMARC's policy decides what happens to failing mail either way, so many domains keep ~all.
What does include:_spf.google.com mean?
It tells receivers to also accept any server listed in Google's own SPF record, _spf.google.com. That's how Google Workspace authorises its sending servers for your domain without you listing their IP addresses.
Is SPF enough to stop spoofing?
No. SPF checks the hidden envelope sender (Return-Path), not the From address people see. DMARC ties SPF and DKIM to the visible From domain and tells receivers what to do when they fail, so you need SPF, DKIM and DMARC together.
My SPF record is longer than 255 characters. Is that a problem?
Not by itself. A single DNS TXT string holds up to 255 characters, so a longer record is stored as several quoted strings in one TXT record, which receivers join back together. Most DNS hosts split long values automatically.
Keep going
Authenticated email. Now make it worth opening.
Atlis tracks what each user does after signup and sends lifecycle emails automatically: onboarding nudges, re-engagement, churn recovery and failed-payment recovery.
Free plan · No credit card · 10-minute setup