What is SPF?
SPF (Sender Policy Framework) is an email authentication protocol defined in RFC 7208. It allows domain owners to specify which mail servers are authorized to send emails on behalf of their domain.
SPF works by publishing a DNS TXT record that lists the IP addresses, hostnames, and third-party services authorized to send email for the domain. When a receiving mail server gets an email, it checks the sender's IP against the SPF record of the domain in the envelope sender (MAIL FROM / Return-Path).
How SPF Works
- You publish an SPF record in your domain's DNS:
v=spf1 ip4:203.0.113.0/24 include:_spf.google.com ~all - A receiver gets an email with Return-Path:
user@yourdomain.com - The receiver queries DNS for
yourdomain.com TXTand finds the SPF record - The receiver checks if the connecting IP matches any authorized source
- Result:
pass,fail,softfail,neutral,temperror, orpermerror
SPF Record Syntax
An SPF record always starts with v=spf1 and contains one or more mechanisms, each optionally preceded by a qualifier.
Mechanisms
| Mechanism | Description | Example |
|---|---|---|
ip4 | Match an IPv4 address or CIDR range | ip4:203.0.113.0/24 |
ip6 | Match an IPv6 address or range | ip6:2001:db8::/32 |
a | Match the A record of the domain | a or a:mail.example.com |
mx | Match the MX records of the domain | mx or mx:example.com |
include | Include another domain's SPF record | include:_spf.google.com |
exists | Check if a DNS A record exists | exists:%{i}.spf.example.com |
all | Catch-all (always matches) | -all (hard fail for everything else) |
redirect | Use another domain's SPF record entirely | redirect=_spf.example.com |
Qualifiers
| Qualifier | Meaning | Result | Recommendation |
|---|---|---|---|
+ (default) | Pass | Authorized sender | Use for known senders |
- | Hard Fail | Unauthorized, reject | Use with -all when confident |
~ | Soft Fail | Suspicious, flag but accept | Use during initial rollout |
? | Neutral | No assertion made | Rarely used |
Real-World Examples
# Basic: Google Workspace only
v=spf1 include:_spf.google.com -all
# Multiple services: Google + Mailchimp + own server
v=spf1 ip4:198.51.100.10 include:_spf.google.com include:servers.mcsv.net -all
# Soft fail during rollout (monitoring phase)
v=spf1 include:_spf.google.com include:amazonses.com ~all
The 10 DNS Lookup Limit
One of the most common and critical SPF issues is the 10 DNS lookup limit. RFC 7208 specifies that SPF evaluation must not require more than 10 DNS lookups. If your SPF record exceeds this limit, the result is permerror — and many receivers will treat this as a failure.
What Counts as a Lookup?
| Mechanism | Lookups | Notes |
|---|---|---|
include: | 1 + nested | Each include is 1 lookup, plus any lookups within the included record |
a | 1 | DNS A record query |
mx | 1 + MX count | MX lookup, then A lookups for each MX server |
redirect= | 1 | Counts as 1 lookup |
exists: | 1 | DNS A record existence check |
ip4: | 0 | No DNS lookup needed |
ip6: | 0 | No DNS lookup needed |
How to Solve "Too Many Lookups"
- Flatten includes: Replace
include:with the actual IP ranges. Use SPF Flattening tools. - Remove unused services: Audit which third-party senders you actually use.
- Use ip4/ip6 directly: These don't count toward the limit.
- Use subdomains: Send marketing emails from
marketing.example.comwith its own SPF record. - Avoid
mxanda: These often waste lookups; useip4:directly instead.
Common SPF Issues & Solutions
Issue 1: Multiple SPF Records
A domain must have exactly one SPF record. Having two or more SPF TXT records is a permerror.
# WRONG: Two separate records
v=spf1 include:_spf.google.com -all
v=spf1 include:amazonses.com -all
# CORRECT: Combined into one
v=spf1 include:_spf.google.com include:amazonses.com -all
Issue 2: Exceeding the 255-Character String Limit
DNS TXT records have a 255-byte string limit. For longer SPF records, split into multiple strings within the same record (DNS handles concatenation).
Issue 3: Using +all
Never use +all — this authorizes the entire internet to send email as your domain. Always use -all or ~all.
Issue 4: Forgetting Third-Party Senders
Common third-party services that need to be in your SPF record:
- Google Workspace:
include:_spf.google.com - Microsoft 365:
include:spf.protection.outlook.com - Amazon SES:
include:amazonses.com - Mailchimp:
include:servers.mcsv.net - SendGrid:
include:sendgrid.net - Zendesk:
include:mail.zendesk.com - Salesforce:
include:_spf.salesforce.com - HubSpot:
include:_spf.hubspot.net
Issue 5: SPF Passing But DMARC Failing
SPF checks the Envelope Sender (Return-Path), not the visible sender (From:). If these don't align, SPF will pass but DMARC Alignment will fail. This is common with third-party senders that use their own Return-Path domain.
Related articles
Introduction to Email Authentication
Why email authentication matters and how SPF, DKIM, and DMARC work together to protect your domain.
ReadDKIM (DomainKeys Identified Mail)
Understanding DKIM: how cryptographic signatures protect email integrity, key management, and selector strategies.
ReadTroubleshooting Guide
Common DMARC, SPF, and DKIM problems and how to diagnose and fix them.
Read