Step 1
Audit senders
List workplace email, newsletters, forms, invoices, support tools and transactional providers.
If an SPF record already exists, update it. Never publish a second one.
Select every service that sends mail using this domain.
Separate multiple include domains with commas or spaces.
Redirect delegates the full policy and replaces the final all mechanism.
Start with ~all. Use -all only after every legitimate sender is included.
Step 1
List workplace email, newsletters, forms, invoices, support tools and transactional providers.
Step 2
Merge every authorized source into one TXT record beginning with v=spf1.
Step 3
Begin with ~all, verify delivery and authentication, then consider moving to -all.
An SPF record is a DNS TXT record that lists the servers allowed to send email for your domain. Receiving mail systems compare the sending server with this policy to help detect spoofed messages.
Use ~all while discovering and testing every legitimate sender. Move to -all after confirming your website, workplace email, newsletters, support system and transaction providers are all authorized.
No. A domain must have only one TXT record beginning with v=spf1. If one already exists, merge new senders into it rather than publishing a second SPF record.
An SPF evaluation may perform no more than 10 DNS lookups. Include, a, mx and redirect can consume lookups, and provider include records can contain additional nested lookups.
Create or update a TXT record at the root of your domain in your DNS provider. The host is usually @, your domain name or left blank, depending on the provider.
Need a memorable address for your next email brand? Browse our premium domains — every name is $1,000 with instant transfer.