Biz-Ai-DMARC / Guides
SPF record syntax
SPF lists the servers allowed to send mail for your domain. The syntax is short, but one limit catches almost everyone: 10 DNS lookups.
The basics
Anatomy of an SPF record
An SPF record is a TXT record on the domain itself (not on a special name like DMARC). It starts with v=spf1, lists mechanisms from left to right, and ends with an all that says what to do with everything else. The first mechanism that matches decides the result. The standard is RFC 7208.
v=spf1 ip4:192.0.2.0/24 include:_spf.mailhost.example mx ~all
Read it as: mail from 192.0.2.0/24, or from a server the mail host authorizes, or from this domain’s MX servers, passes. Anything else soft-fails.
Qualifiers
Each mechanism can carry a prefix that sets the result when it matches:
+pass (the default when there is no prefix)-fail: not authorized~softfail: probably not authorized?neutral: no statement
In practice the prefix only appears on all: -all or ~all.
Mechanisms
What you can list
ip4 and ip6
An address or range, such as ip4:192.0.2.10 or ip6:2001:db8::/32. No DNS lookup, so free against the limit.
include
Uses another domain’s SPF record, which is how you authorize a mail provider: include:_spf.provider.example. Costs one lookup, plus every lookup inside the included record. If the included domain has no SPF record, the whole check errors.
a and mx
The domain’s own address records, or its mail servers. One lookup each. mx also resolves every mail server it finds, and more than 10 mail server names is an error.
all
Matches everything, so it goes last. -all or ~all. Never publish +all: it authorizes the entire internet.
exists
An advanced mechanism that passes if a constructed name resolves. Rarely needed outside large mail platforms. One lookup.
ptr
Checks reverse DNS. The standard says not to use it: it is slow, unreliable and costs lookups. Replace it with ip4/ip6 or include.
Modifiers
redirect= hands the whole check to another domain’s record (one lookup), useful for many domains sharing one policy. exp= names an explanation string and is rarely used.
The limit
10 DNS lookups, and what breaks it
To stop SPF being used to flood DNS, a check may make at most 10 lookups. include, a, mx, ptr, exists and redirect each count, including every one nested inside included records. ip4, ip6 and all are free.
Go over 10 and the result is a permerror: SPF fails for every message, including your legitimate mail. Each mail provider’s include often costs three or four lookups by itself, so four or five services are usually enough to break it. There is also a limit of two lookups that return nothing, which catches includes pointing at domains that no longer exist.
Staying under the limit
- Remove services you no longer use. Old includes are the most common cause.
- Let services that support it rely on DKIM alignment instead of SPF. DMARC needs only one of the two.
- Move a bulk sender to a subdomain such as
news.example.comwith its own SPF record. - “Flattening” (replacing includes with the IP addresses behind them) fixes the count but breaks silently when a provider changes its servers. Avoid it unless something keeps it updated.
Getting it right
Common mistakes
- Two SPF records on the same domain. That is a permerror. Merge them into one.
- Expecting subdomains to inherit SPF. They do not. Every name that appears as an envelope sender needs its own record.
- Forgetting domains that never send mail. Publish
v=spf1 -allon them, plus a DMARC record withp=reject, so nobody can use them either.
- A record that is too long. A single DNS string holds 255 characters; longer records are split into several quoted strings that receivers join. Keep the whole record short enough to fit a normal DNS answer.
- Relying on
-allfor protection. SPF on its own does not protect the visible From address. DMARC does.~allwith an enforced DMARC policy is the common, safe combination.
Keep reading
More guides and free tools
Guides
- DMARC record tags: Every tag in a DMARC record, what it does and what to set it to.
- DMARC alignment: Why passing SPF or DKIM is not enough, and relaxed versus strict.
- DMARC glossary: The terms used in records and reports, in plain words.
- Email authentication standards: The IETF documents that define SPF, DKIM and DMARC, with links to the source.
Free tools
- DMARC record generator: build a record for the current standard.
- DMARC report viewer: read an aggregate report as a table, in your browser.
- Biz-Ai-DMARC: reports collected, summarized and alerted on for you.
Tell us what is not working
A 30-minute call, no pitch deck. We will tell you what we would do first, and whether we are the right people to do it.