Key points at a glance
- SPF lists in the DNS the servers allowed to send emails for your domain.
- There may only be one SPF record, and it may trigger at most 10 DNS lookups.
- SPF alone does not protect against spoofed senders in the mailbox – that takes DMARC.
What SPF does
With SPF (Sender Policy Framework, RFC 7208) you publish a list in the DNS of the servers allowed to send emails for your domain. The receiving server checks whether the email comes from one of these servers. Example: example.com TXT “v=spf1 include:_spf.example.net -all”.
- Email arrivesThe recipient sees the technical sender domain and the address of the sending server.
- DNS lookupIt reads that domain’s SPF record.
- ComparisonIs the sending server on the list?
- ResultMatch: passed. Otherwise the final rule applies, -all or ~all.
The key building blocks
- include: takes over the list of a service, such as your mail provider or newsletter tool.
- ip4 and ip6: allow individual addresses or networks.
- a and mx: allow the servers behind the A or MX record.
- -all (hard) or ~all (soft): defines what happens with all remaining servers.
The three most common mistakes
- More than one SPF record: there must be exactly one, otherwise SPF is invalid.
- More than 10 DNS lookups: every include counts, including nested ones. From the eleventh lookup, SPF counts as an error (“permerror”).
- Forgotten services: a shop, CRM or ticketing system sends in your name but is not listed in the record.
Watch the limit of 10 lookups
Including many services via include quickly exceeds the limit. SPF then becomes invalid and no longer helps any of your emails – not even the genuine ones.
Why SPF alone is not enough
SPF only checks the technical sender address (return path), not the address shown in the mailbox. A fraudster can therefore send an email with your visible address that passes SPF for their own domain. SPF also breaks when an email is forwarded. Only DMARC links SPF to the visible address.
Tip for domains that send no mail
Protect domains that never send email with “v=spf1 -all”. That way, every recipient knows no genuine email ever comes from that domain.
How DomainRadar helps
DomainRadar continuously checks your SPF record, counts the DNS lookups, detects duplicate or invalid records and notifies you when something changes. If the limit gets tight, DomainRadar can provide a hosted SPF that consolidates the lookups.
The domain check stays free. Afterwards you test Business for 14 days – no credit card, the trial ends on its own.