NEW CASE
Antana

We create digital solutions that work for businesses


Give us a call +38 (066) 35-14-529

Let's take the first step towards your website — write to us

Close
Tools

SPF Record Generator

A correct SPF record for your domain.

Building an SPF record

Order matters: gather the full list of senders first, then compose the record.

1 List every source Hosting mail, the contact form, CRM, newsletter service, accounting software. Any source you miss starts landing in spam.
2 Get each service’s include Google, Microsoft and mailing services publish a ready-made string in their docs. Nothing needs inventing.
3 Combine into one record Two SPF records on a domain is an error that fails the check outright. There must be exactly one line.
4 Start with ~all A soft policy blocks nothing while you verify. Move to -all once you are sure everything arrives.

Limits people forget

Ten DNS lookups Every include, a or mx is a lookup. Exceeding the limit invalidates the record and SPF stops working entirely.
Nested includes count too One include can contain three more inside. The limit runs out faster than the record looks.
255 characters per string A long record is split into chunks by DNS. Most servers handle it, but not all.
Avoid the ptr mechanism A deprecated mechanism many receivers simply ignore. Use ip4 or include instead.

Ready includes for common services

The most common senders and what they ask you to add.

Google Workspace include:_spf.google.com — covers all Google mail, including sending through their servers.
Microsoft 365 include:spf.protection.outlook.com — the standard line for Microsoft business mail.
Your host Usually an include with the provider domain. The exact string is in their docs or control panel.
Newsletter service SendPulse, Mailchimp and others give you a line when you connect a domain. Without it, mail goes to spam.

Create an SPF record for a domain

The generator builds a correct SPF record from your data: specify the IPs of your own mail servers, add includes for services (e.g. _spf.google.com for Google Workspace or spf.protection.outlook.com for Microsoft 365) and choose a policy for the rest of the world. Copy the ready string in one click.

Add the resulting record to the domain DNS as a TXT record for the root (@). Remember the key rules: there must be only one SPF record, at most 10 DNS lookups (each include counts), and start with the soft ~all policy, moving to -all after verifying all your mail passes.

FAQ

How to create an SPF record?
Specify your mail server IPs and services (e.g. include:_spf.google.com for Gmail), choose a policy for the rest — the generator builds a ready string.
Where to add the SPF record?
In your domain DNS control panel as a TXT record for the domain root (@). The value is the generated string starting with v=spf1.
What to put in include?
Domains of mail services that send your mail: _spf.google.com (Google), spf.protection.outlook.com (Microsoft), etc. Your provider gives them.
How long does a change take?
After adding the TXT record, changes propagate in DNS from a few minutes to 24-48 hours due to caching.
Telegram Viber Call us