How to use the SPF record generator
Enter your domain, add the include value of every service that sends mail for it, add the IP addresses of your own mail servers, and choose how receivers should treat everyone else. The generator builds one record that starts with v=spf1. You publish it as a TXT record on your domain. Google says SPF can take up to 48 hours to start working after you add the record.
If you use Google Workspace and nothing else sends your mail, the record you need is v=spf1 include:_spf.google.com ~all.
Before you start
You need three things.
- Access to the DNS settings of your domain, usually at your domain host.
- A list of every server and service that sends mail with your domain: your mailbox provider, your marketing platform, your help desk, your billing system and any web server that sends forms or receipts.
- Your current SPF record, if there is one. Select Check current SPF in the generator, or look for a TXT record that starts with
v=spf1at your DNS host.
A domain can have only one SPF record. If you already have one, add its sources to the generator and replace the old record. Do not add a second one.
Fill in the generator
| Field | What to enter | Adds |
|---|---|---|
| Domain name | The domain in your From address | example.com |
| Your own servers | Turn on if mail leaves from your web server or your MX servers | a |
| IPv4 and IPv6 | Addresses or ranges of servers you run | ip4:203.0.113.10 |
| Include domains | The include value from each service that sends mail for you | include:_spf.google.com |
| Policy | ~all while you set up, -all once the list is complete | ~all |
The results show three items.
| Item | What it tells you |
|---|---|
| SPF record value | The text to paste into the Value field of your TXT record |
| DNS lookups | How many of the 10 allowed lookups the record uses before nested includes |
| Warnings | Invalid addresses, more than 10 lookups, or a record over 255 characters |
Each include, a and mx costs a DNS lookup. An include can also contain more includes of its own, and those count too. SPF fails when a record needs more than 10 lookups.
Publish the SPF record
Add one TXT record at your DNS host with these values.
| Field | Value |
|---|---|
| Type | TXT |
| Host, Name or Alias | @ or leave blank, for the root domain |
| Value | The SPF record value from the generator |
| TTL | The default, or 3600 |
Save the record. If an SPF record already exists, edit that record instead of creating a new one.
Each domain and subdomain that sends mail needs its own record. SPF on example.com does not cover news.example.com.
Check that it works
- Wait for the DNS change to spread. Google gives up to 48 hours.
- Send a message to a Gmail address that is not the address you sent from.
- Open the message, select More next to Reply, then select Show original.
- Find the Authentication-Results header and look for
spf=pass.
Repeat the test from each service that sends your mail. A pass from your mailbox provider does not prove your marketing platform is listed.
Fix common SPF problems
| What you see | Cause | Fix |
|---|---|---|
| spf=permerror | The domain has two SPF records. | Merge both into one record and delete the other. |
| spf=permerror and there is only one record | The record needs more than 10 DNS lookups. | Remove services you no longer use, or replace includes with ip4 or ip6 ranges. |
| spf=softfail or spf=fail | The sending server is not in the record. | Add the service's include value or the server's IP address. |
| spf=none | No SPF record was found, or it is on the wrong host name. | Publish the record on @, not on a subdomain or on www. |
| Passes from one service, fails from another | Only some senders are listed. | List every service that sends with your domain in one record. |
| Fails on forwarded mail | Forwarding sends your message from a server you do not control. | Set up DKIM. DKIM signatures survive forwarding. |
| DNS host rejects the value | Some hosts limit one TXT string to 255 characters. | Split the value into several quoted strings in one record, or remove sources. |
| The record was added within the last 48 hours | DNS has not finished updating. | Test again after 48 hours. |
Why TrueEmailer for deliverability
Receiving servers check SPF on every message to see whether the sending server is allowed to send for your domain. Google requires SPF or DKIM from everyone who sends to personal Gmail accounts, and all three of SPF, DKIM, and DMARC from senders above 5,000 messages a day.
Doing SPF by hand leaves room for the errors in the table above. A second record, a missing sender or an eleventh lookup is easy to create and slow to find, because DNS changes take hours to confirm.
TrueEmailer removes that setup step.
- SPF, DKIM, and DMARC are configured at setup, so authentication is in place before the first send. Need DKIM too? Use the free DKIM generator.
- Mail leaves from pre-warmed SMTP infrastructure. See deliverability and warmup.
A passing SPF check proves the server was allowed to send for your domain. It does not give you a good reputation. Complaint rates, list quality, and message content still decide where mail lands, and no tool removes that work. Keep your list clean with the free email verifier.
SPF record generator FAQ
What is an SPF record?
+
An SPF record is a TXT record in your domain's DNS that lists the servers allowed to send mail for the domain. Receiving servers compare the sending server's IP address with this list.
Can a domain have two SPF records?
+
No. A domain can have only one SPF record. When there are two, SPF fails. Merge every sender into one record.
Should I use ~all or -all?
+
~all marks mail from unlisted servers as suspicious, and is the usual choice while you confirm every sender is listed. Google's own example record ends in ~all. -all tells receivers that unlisted servers are not allowed. Use it once you are sure the list is complete.
Do I need SPF if I already have DKIM?
+
Set up both. Google requires SPF or DKIM from every sender to personal Gmail accounts, and all three of SPF, DKIM and DMARC from bulk senders.
Does SPF cover my subdomains?
+
No. SPF applies only to the exact domain it is published on. Each subdomain that sends mail needs its own SPF record.
How long until SPF works?
+
Google says up to 48 hours after you add the record. Test again after that window before you change anything.