Skip to content

SPF record syntax

Biz-Ai-DMARC / Guides

SPF record syntax

SPF lists the servers allowed to send mail for your domain. The syntax is short, but one limit catches almost everyone: 10 DNS lookups.

The basics

Anatomy of an SPF record

An SPF record is a TXT record on the domain itself (not on a special name like DMARC). It starts with v=spf1, lists mechanisms from left to right, and ends with an all that says what to do with everything else. The first mechanism that matches decides the result. The standard is RFC 7208.

v=spf1 ip4:192.0.2.0/24 include:_spf.mailhost.example mx ~all

Read it as: mail from 192.0.2.0/24, or from a server the mail host authorizes, or from this domain’s MX servers, passes. Anything else soft-fails.

Qualifiers

Each mechanism can carry a prefix that sets the result when it matches:

  • + pass (the default when there is no prefix)
  • - fail: not authorized
  • ~ softfail: probably not authorized
  • ? neutral: no statement

In practice the prefix only appears on all: -all or ~all.

Mechanisms

What you can list

ip4 and ip6

An address or range, such as ip4:192.0.2.10 or ip6:2001:db8::/32. No DNS lookup, so free against the limit.

include

Uses another domain’s SPF record, which is how you authorize a mail provider: include:_spf.provider.example. Costs one lookup, plus every lookup inside the included record. If the included domain has no SPF record, the whole check errors.

a and mx

The domain’s own address records, or its mail servers. One lookup each. mx also resolves every mail server it finds, and more than 10 mail server names is an error.

all

Matches everything, so it goes last. -all or ~all. Never publish +all: it authorizes the entire internet.

exists

An advanced mechanism that passes if a constructed name resolves. Rarely needed outside large mail platforms. One lookup.

ptr

Checks reverse DNS. The standard says not to use it: it is slow, unreliable and costs lookups. Replace it with ip4/ip6 or include.

Modifiers

redirect= hands the whole check to another domain’s record (one lookup), useful for many domains sharing one policy. exp= names an explanation string and is rarely used.

The limit

10 DNS lookups, and what breaks it

To stop SPF being used to flood DNS, a check may make at most 10 lookups. include, a, mx, ptr, exists and redirect each count, including every one nested inside included records. ip4, ip6 and all are free.

Go over 10 and the result is a permerror: SPF fails for every message, including your legitimate mail. Each mail provider’s include often costs three or four lookups by itself, so four or five services are usually enough to break it. There is also a limit of two lookups that return nothing, which catches includes pointing at domains that no longer exist.

Staying under the limit

  • Remove services you no longer use. Old includes are the most common cause.
  • Let services that support it rely on DKIM alignment instead of SPF. DMARC needs only one of the two.
  • Move a bulk sender to a subdomain such as news.example.com with its own SPF record.
  • “Flattening” (replacing includes with the IP addresses behind them) fixes the count but breaks silently when a provider changes its servers. Avoid it unless something keeps it updated.

Getting it right

Common mistakes

  • Two SPF records on the same domain. That is a permerror. Merge them into one.
  • Expecting subdomains to inherit SPF. They do not. Every name that appears as an envelope sender needs its own record.
  • Forgetting domains that never send mail. Publish v=spf1 -all on them, plus a DMARC record with p=reject, so nobody can use them either.
  • A record that is too long. A single DNS string holds 255 characters; longer records are split into several quoted strings that receivers join. Keep the whole record short enough to fit a normal DNS answer.
  • Relying on -all for protection. SPF on its own does not protect the visible From address. DMARC does. ~all with an enforced DMARC policy is the common, safe combination.

Keep reading

More guides and free tools

Guides

Free tools

Tell us what is not working

A 30-minute call, no pitch deck. We will tell you what we would do first, and whether we are the right people to do it.

Powered by Hostinger

This site is hosted on Hostinger. Some links here are affiliate links and may earn us a commission at no extra cost to you. We recommend only what we use ourselves or built ourselves. Read the full disclosure.