Back to BlogEmail Security Guides

What is an SPF Record? Complete Guide to Email Authentication

StopSpoofingMe TeamPublished Updated 8 min read

Email spoofing affects 92% of organizations worldwide, making SPF records one of the most important DNS security measures you can implement. But what exactly is an SPF record, and how does it protect your domain?

Understanding SPF Records

An SPF (Sender Policy Framework) record is a DNS TXT record that specifies which mail servers are authorized to send email on behalf of your domain. Think of it as a whitelist that tells receiving mail servers "these are the only servers allowed to send email from our domain."

How SPF Records Work

When someone sends an email claiming to be from your domain, the receiving mail server:

  1. Looks up your SPF record in your DNS
  2. Checks if the sending server is authorized in your SPF record
  3. Accepts or rejects the email based on your SPF policy

Real-World Example

Let's say your domain is example.com and you use Google Workspace for email. Your SPF record might look like:

v=spf1 include:_spf.google.com -all

This tells mail servers: "Only Google's servers can send email from example.com, reject everything else."

Why SPF Records Are Critical in 2026

Email fraud has risen sharply in recent years, with the average business email compromise incident costing companies roughly $125,000 according to FBI IC3 data. Without proper SPF configuration:

  • Scammers can impersonate your domain
  • Your legitimate emails may be marked as spam
  • Your domain reputation suffers
  • Customers lose trust in your brand

SPF Record Syntax Breakdown

SPF records follow a specific format with mechanisms and qualifiers:

Basic Structure

v=spf1 [mechanisms] [qualifier]

Common Mechanisms

  • include: Reference another domain's SPF record
  • mx: Use your domain's MX records as authorized servers
  • a: Use your domain's A record as authorized servers
  • ip4/ip6: Specify exact IP addresses

Qualifiers

  • +all: Pass (allow all servers) - NEVER USE
  • -all: Fail (strict policy, reject unauthorized)
  • ~all: Soft fail (less strict, may mark as suspicious)
  • ?all: Neutral (no policy specified)

Step-by-Step SPF Setup Guide

Step 1: Identify Your Email Providers

List all services that send email from your domain:

  • Email hosting provider (Gmail, Outlook, etc.)
  • Marketing platforms (Mailchimp, Constant Contact)
  • CRM systems (Salesforce, HubSpot)
  • Transactional email services (SendGrid, Mailgun)

Step 2: Build Your SPF Record

Start with your primary email provider and add others:

# Google Workspace only
v=spf1 include:_spf.google.com -all

# Google + Mailchimp + Custom server
v=spf1 include:_spf.google.com include:servers.mcsv.net ip4:203.0.113.1 -all

Step 3: Publish to DNS

Add the SPF record as a TXT record in your DNS:

  • Host/Name: @ (root domain) or leave blank
  • Type: TXT
  • Value: Your SPF record string
  • TTL: 3600 (1 hour) or your provider's default

Step 4: Test Your SPF Record

Use tools like:

  • StopSpoofingMe's free SPF checker
  • MXToolbox SPF Record Lookup
  • Google Admin Toolbox

Common SPF Mistakes to Avoid

1. Using +all or no qualifier

Wrong: v=spf1 include:_spf.google.com (no qualifier)
Right: v=spf1 include:_spf.google.com -all

2. Too many DNS lookups

SPF records are limited to 10 DNS lookups. Each include: counts as one lookup.

3. Multiple SPF records

Only one SPF record per domain. Multiple SPF records invalidate all of them.

4. Forgetting about subdomains

Subdomains need their own SPF records unless they don't send email.

Advanced SPF Configuration

For Complex Email Infrastructure

v=spf1 mx include:_spf.google.com include:servers.mcsv.net include:sendgrid.net ip4:203.0.113.0/24 -all

Using SPF Macros

Advanced users can use macros for dynamic SPF records:

v=spf1 exists:%{i}._spf.%{d} -all

Monitoring SPF Performance

After implementing SPF:

  1. Monitor DMARC reports to see SPF pass/fail rates
  2. Check email deliverability to major providers
  3. Review authentication-results headers in received emails
  4. Update records when adding new email services

SPF Best Practices for 2026

✅ Use -all for strict enforcement
✅ Start with ~all for testing, then upgrade to -all
✅ Keep records under 255 characters
✅ Document your SPF record configuration
✅ Review and update quarterly
✅ Implement DMARC for complete protection

❌ Don't use +all (allows anyone to send)
❌ Don't exceed 10 DNS lookups
❌ Don't create multiple SPF records
❌ Don't forget to test after changes

What's Next After SPF?

SPF is just the first step in email authentication. For complete protection, also implement:

  1. DMARC - Tells receivers what to do with SPF/DKIM failures
  2. DKIM - Cryptographically signs your emails
  3. MTA-STS - Enforces TLS encryption
  4. TLS-RPT - Provides encryption failure reports

Get Professional Help

Setting up SPF records incorrectly can break your email delivery. If you're not confident in your configuration:

  • Use StopSpoofingMe's free SPF wizard for guided setup
  • Get a professional security audit ($749 setup, $19/month monitoring)
  • Contact our team for urgent fixes ($999 same-day service)

92% of domains are vulnerable to email spoofing. Don't let yours be one of them.


Need help with SPF setup? Use our free SPF wizard or scan your domain to check your current configuration.

Related Topics

what is SPF recordSPF record explainedemail authenticationprevent email spoofingSPF setup guideDNS SPF recordemail security 2026domain email protection

Ready to Secure Your Email?

Check your domain's email security status with our free scanner, or get professional help setting up DMARC, SPF, and DKIM.