Try free for 14 days

Basics

SPF explained: who may send for your domain?

SPF is the oldest and best-known building block of email security. It is quick to set up but often faulty: one forgotten service or one entry too many is enough for your own emails to be rejected.

3 min readHow well is your domain protected? Check my domain for free

Key points at a glance

  • SPF lists in the DNS the servers allowed to send emails for your domain.
  • There may only be one SPF record, and it may trigger at most 10 DNS lookups.
  • SPF alone does not protect against spoofed senders in the mailbox – that takes DMARC.

What SPF does

With SPF (Sender Policy Framework, RFC 7208) you publish a list in the DNS of the servers allowed to send emails for your domain. The receiving server checks whether the email comes from one of these servers. Example: example.com TXT “v=spf1 include:_spf.example.net -all”.

How the recipient checks SPF
  1. Email arrivesThe recipient sees the technical sender domain and the address of the sending server.
  2. DNS lookupIt reads that domain’s SPF record.
  3. ComparisonIs the sending server on the list?
  4. ResultMatch: passed. Otherwise the final rule applies, -all or ~all.

The key building blocks

  • include: takes over the list of a service, such as your mail provider or newsletter tool.
  • ip4 and ip6: allow individual addresses or networks.
  • a and mx: allow the servers behind the A or MX record.
  • -all (hard) or ~all (soft): defines what happens with all remaining servers.

The three most common mistakes

  • More than one SPF record: there must be exactly one, otherwise SPF is invalid.
  • More than 10 DNS lookups: every include counts, including nested ones. From the eleventh lookup, SPF counts as an error (“permerror”).
  • Forgotten services: a shop, CRM or ticketing system sends in your name but is not listed in the record.

Watch the limit of 10 lookups

Including many services via include quickly exceeds the limit. SPF then becomes invalid and no longer helps any of your emails – not even the genuine ones.

Why SPF alone is not enough

SPF only checks the technical sender address (return path), not the address shown in the mailbox. A fraudster can therefore send an email with your visible address that passes SPF for their own domain. SPF also breaks when an email is forwarded. Only DMARC links SPF to the visible address.

Tip for domains that send no mail

Protect domains that never send email with “v=spf1 -all”. That way, every recipient knows no genuine email ever comes from that domain.

How DomainRadar helps

DomainRadar continuously checks your SPF record, counts the DNS lookups, detects duplicate or invalid records and notifies you when something changes. If the limit gets tight, DomainRadar can provide a hosted SPF that consolidates the lookups.

The domain check stays free. Afterwards you test Business for 14 days – no credit card, the trial ends on its own.

More guides

How does your domain measure up?

DomainRadar continuously checks the SPF, DKIM and DMARC of your domains and tells you in plain words what to do.