DNS RobotDNS Propagation Checker
HomeDNS LookupWHOIS LookupIP LookupSSL Check
DNS RobotDNS Propagation Checker

Next-generation DNS propagation toolkit

Privacy PolicyTerms of ServiceAbout UsBlogContact

DNS Tools

DNS LookupDNS Speed TestDomain to IPNS LookupMX LookupView all

Email Tools

Email CheckerSPF Record CheckerDMARC CheckerDKIM CheckerSMTP Test ToolView all

Website Tools

Website Down CheckerWHOIS LookupHosting CheckerDomain AvailabilitySubdomain FinderView all

Network Tools

Ping ToolTraceroutePort CheckerHTTP Headers CheckSSL Certificate CheckView all

IP Tools

IP LookupWhat Is My IPIPv6 TestWebRTC Leak TestRouter LoginView all

Utility Tools

QR Code ScannerQR Code GeneratorUPI QR Code GeneratorWiFi QR Code GeneratorMorse Code TranslatorView all
© 2026 DNS Robot. Developed by ❤ Shaik Brothers
All systems operational
Made with
  1. Home
  2. /
  3. Email Tools
  4. /
  5. SPF Record Generator

SPF Record Generator

Create a valid SPF record for your domain in seconds. Tick the email services that send for you, add your own servers, choose ~all or -all, and copy a TXT record checked against SPF's 10 DNS lookup limit. Already have a record? Import it and edit it.

23 Email Providers10-Lookup CounterImport Current SPFFree, No Sign-up

Email services that send for this domain

Tick each service that sends mail with your domain in the envelope sender. Services that use their own bounce domain (for example SendGrid with automated security, Postmark, or Amazon SES without a custom MAIL FROM) don't need an include.

Your own mail servers

What should receivers do with mail from other servers?

Your SPF record

1 of 10 DNS lookups
v=spf1 mx ~all
TypeTXTHost / Name@Length14 characters

Valid SPF syntax and within the 10-lookup limit.

Publish it as a single TXT record at your domain (replace any existing v=spf1 record, never add a second one), then check it with the SPF Checker.

The record is built in your browser. Include lookups use Google Public DNS over HTTPS.

Advertisement

What Is an SPF Record?

An SPF record (Sender Policy Framework, RFC 7208) is a TXT record on your domain that lists the servers allowed to send email for it. When a message arrives, the receiving server looks up the SPF record of the envelope sender's domain (the Return-Path, not the visible From address) and checks whether the sending IP is on the list.

A domain can have only one SPF record. Two records starting with v=spf1 make every SPF check fail with PermError, so when you add a new service you edit the existing record instead of adding another. Since February 2024 Gmail and Yahoo expect every sender to use SPF or DKIM, and bulk senders to use SPF, DKIM and DMARC together.

SPF record generator output for Google Workspace, Microsoft 365, mx and one IPv4 server, with a 3 of 10 lookup count
Tick your email services, add your own servers, pick a policy and copy the record. The counter follows every nested include.

How to Create an SPF Record

1
List everything that sends as you

Your mailbox provider, newsletter and transactional services, help desk, CRM, and any server or website that sends mail from your domain. Missing one is the most common reason SPF fails.

2
Tick the services and add your servers

Pick each provider above, add any other include domains, and enter your own servers as IPv4 or IPv6 addresses. Use mx only if your inbound mail servers also send.

3
Choose the policy

~all (soft fail) is the usual start. Switch to -all (fail) when you're sure the list is complete. Keep an eye on the lookup counter: it must stay at 10 or below.

4
Publish one TXT record

Add it as a TXT record with host @ (or the subdomain that sends mail), replacing any existing v=spf1 record. Then confirm it with the SPF Checker.

Advertisement

SPF Record Syntax Explained

An SPF record is a list of terms read from left to right. The first one that matches the sending IP decides the result.

Requiredv=spf1

The version tag. It must be the first term, and it's how receivers recognise the TXT record as SPF.

1 lookup + nestedinclude:domain

Authorizes everything in another domain's SPF record, such as include:_spf.google.com. Every lookup inside that record counts toward your limit too.

0 lookupsip4: and ip6:

Authorize one address or a CIDR range, for example ip4:203.0.113.10 or ip6:2001:db8::/48. They cost no DNS lookups.

1 lookup eacha and mx

Authorize the IPs of the domain's A/AAAA record or of its MX hosts. Handy, but each costs a lookup, and mx can cost up to 10 more queries inside.

The ending~all, -all, ?all

What to do with every other server: soft fail, fail, or neutral. Never publish +all, which lets anyone send as your domain.

Advancedredirect=, exists:, ptr

redirect= hands the whole check to another domain's record. exists: is used with macros by some large senders. ptr is slow, and RFC 7208 says not to publish it.

~all vs -all: Soft Fail or Fail?

-all tells receivers that mail from any unlisted server fails SPF, and many will reject it. ~all marks it as a soft fail: receivers shouldn't reject it on that alone, but may treat it as suspicious. ?all is neutral and offers no protection.

Google's Workspace instructions use ~all and Microsoft's Microsoft 365 example uses -all. Both work. Once you publish DMARC, the DMARC policy (p=quarantine or p=reject) decides what happens to failing mail, so many domains keep ~all to avoid rejecting legitimate forwarded mail and let DMARC do the enforcing. If the domain sends no email at all, publish v=spf1 -all.

Advertisement

SPF Record Examples

Copy the one closest to your setup, or build your own with the generator above. Each is a single TXT record at your domain.

Google Workspace
v=spf1 include:_spf.google.com ~all
Microsoft 365 (Office 365)
v=spf1 include:spf.protection.outlook.com -all
Google Workspace plus Mailgun and your own server
v=spf1 ip4:203.0.113.10 include:_spf.google.com include:mailgun.org ~all
Zoho Mail (zoho.com data center)
v=spf1 include:zohomail.com ~all
Your own mail servers only
v=spf1 mx ip4:198.51.100.0/24 ip6:2001:db8::/48 -all
A domain that never sends email
v=spf1 -all

The 10 DNS Lookup Limit

RFC 7208 caps an SPF check at 10 DNS lookups. Every include, a, mx, ptr, exists and redirect costs one, and so does every one of those inside the records you include. ip4, ip6 and all are free. A check that needs an 11th lookup stops with PermError, which counts as an SPF failure for DMARC. Receivers should also allow no more than 2 void lookups (names that don't exist or return no records).

Providers don't all cost the same. We counted each include on 5 October 2026, nested lookups included:

1 lookupGoogle Workspace, Microsoft 365

_spf.google.com and spf.protection.outlook.com list their IP ranges directly. Amazon SES, Brevo, Mailjet, Zendesk and Fastmail also cost 1.

2 lookupsZoho, SendGrid, Proton, Salesforce

Each points to one more record of its own.

3 to 4 lookupsGoDaddy, Hostinger, Titan, Namecheap

Hosting mailboxes often chain several includes.

5 to 7 lookupsMailgun, iCloud, Freshdesk, Yandex

One of these plus a few other services can use up the whole budget.

Advertisement

How to Fix an SPF Record With Too Many Lookups

  • Remove services you no longer use. Old newsletter tools and trial accounts are the usual culprits.

  • Replace `a` and `mx` with `ip4`/`ip6` when your own servers have fixed addresses.

  • Move bulk mail to a subdomain such as news.example.com, with its own SPF record and its own 10 lookups.

  • Check whether a service needs an include at all. Many senders use their own bounce domain, so SPF passes on theirs and DMARC alignment comes from DKIM.

  • Be careful with SPF flattening. Replacing includes with copied IP lists works until a provider changes its IPs, then mail starts failing without warning.

Common SPF Mistakes

  • Two SPF records on the same domain, for example one per provider. Merge them into one.

  • Using +all, which authorizes the whole internet.

  • Publishing the record on the wrong name. SPF is checked on the envelope sender's domain, and subdomains don't inherit it.

  • Adding mechanisms after all. Receivers never evaluate them, so those senders aren't authorized.

  • Forgetting a sender, such as the web server that sends contact-form mail.

  • Using the old SPF record type (type 99). RFC 7208 discontinued it: publish TXT only.

Advertisement

SPF, DKIM and DMARC Work Together

SPF alone doesn't stop someone faking the From address your readers see. DKIM signs each message, and DMARC ties both to the visible From domain and tells receivers what to do when they fail. Set up all three:

SPF Checker

Verify the published record, its nested includes and its lookup count.

DKIM Record Generator

Create a DKIM key pair and the selector._domainkey TXT record.

DMARC Record Generator

Build a DMARC policy with reporting addresses.

Email Header Analyzer

Read SPF, DKIM and DMARC results from a real message.

SPF Record Generator FAQ

It builds the TXT record that tells receiving mail servers which servers may send email for your domain. You pick your providers and servers, and the generator writes valid SPF syntax and checks the 10-lookup limit for you.

Advertisement