SPF record generator

Pick the services that send your email, add your own servers and get a valid SPF record with the right includes, a lookup count and the right ending.

Build your SPF record

Services that send as your domain
Your own servers

One per line or comma separated. CIDR ranges are fine and cost no lookups.

Domains only, comma separated, with or without include:.

0 / 10DNS lookups, at least. Nested includes add more.
Your SPF record
HostTypeValue
@TXT
v=spf1 ~all
Replace any existing v=spf1 record; a domain can have only one.

The count covers the top level of the record only. After publishing, run the SPF checker to count every nested lookup.

  • Note: No senders selected, so this record authorizes no one. That’s right for a domain that never sends mail; use “v=spf1 -all” for it.

An SPF record is one TXT record at your domain’s root (@) that starts with v=spf1, lists every server or service that sends mail as your domain, and ends with ~all or -all. Use the include each provider documents, keep the total under 10 DNS lookups, and publish only one SPF record per domain.

Not every sender needs an include

SPF checks the envelope sender (the Return-Path, or bounce address), not the From address people see. Many email platforms send with their own bounce domain, so your SPF record isn’t checked at all for their mail. For DMARC, those services pass through DKIM signed with your domain instead. Adding their include to your record costs a lookup and changes nothing.

ServiceInclude in your root SPF?Why
MailchimpNoMailchimp’s domain authentication is two DKIM CNAMEs and a DMARC record; its bounce domain is Mailchimp’s own. Mailchimp Transactional (Mandrill) also authenticates through DKIM.
PostmarkNoPostmark says an include is no longer required: it uses its own Return-Path, or a custom Return-Path subdomain you CNAME to Postmark.
Amazon SESNoBy default SES bounces through amazonses.com. With a custom MAIL FROM domain, publish v=spf1 include:amazonses.com ~all on that MAIL FROM subdomain (such as mail.example.com), not on your root domain.
SendGrid (automated security on)NoIts CNAMEs point a subdomain at SendGrid, which maintains SPF there for you.
HubSpotOnly if HubSpot shows oneOn shared IPs HubSpot’s own SPF covers the bounce domain. When HubSpot’s domain settings list an SPF value, it’s specific to your account.

Staying under 10 DNS lookups

Each include:, a, mx, exists: and redirect= costs one lookup, and so does everything inside an included record. ip4: and ip6: are free. Above 10, receivers return a permanent error and SPF fails for all your mail. The generator counts the top level; the SPF checker resolves the whole tree once the record is live. If you’re close to the limit, fixing too many SPF lookups covers your options. DMARC Dojo hosts your SPF record and refuses changes that would go over the limit.

~all, -all or ?all?

  • ~all (soft fail) is the safe default. DMARC counts a soft fail as not passing, so with DMARC at p=reject, spoofed mail that fails SPF and DKIM is still rejected.
  • -all (fail) is fine once you’re sure every sender is listed. Some receivers reject on an SPF fail before checking DKIM, which can drop forwarded mail that DKIM would have saved.
  • ?all (neutral) means “no opinion”. It never fails anyone, so avoid it. Never use +all.

New to SPF? Read what SPF is and how it works.

Frequently asked questions

Where do I put the SPF record?

At the root of the domain in your Return-Path, as a TXT record. Most DNS hosts use @ (or a blank name) for the root. Subdomains that send mail need their own record, because SPF isn’t inherited.

I already have an SPF record. Do I add a new one?

No. Edit the existing record and add the new include before the all term. Two v=spf1 records at the same name make SPF fail with a permanent error.

Should I list my website’s server with a?

Only if that server sends mail directly, for example a contact form using the server’s own mail function. If your site sends through an email API or SMTP service, include that service instead.

Is there a length limit for SPF records?

Each quoted string in a TXT record is capped at 255 characters, but one record can hold several strings that receivers join together. RFC 7208 asks that the DNS answer for your SPF record fit in 512 bytes, so keep it well under that.

What should the SPF record be for a domain that doesn’t send email?

v=spf1 -all. It tells receivers no server is allowed to send as that domain. Pair it with a DMARC record at p=reject for parked domains. See RFC 7208 for the full syntax.