Skip to content

SPF record generator

Tick every service that sends email as your domain and copy one valid SPF record. The lookup counter warns you before you hit the limit of 10.

Who sends email as your domain?

Your SPF record

Publish as a single TXT record at the root of your domain (host "@"). Replace any existing v=spf1 record; never add a second one.

v=spf1 include:_spf.google.com ~all

About 1 of 10 DNS lookups used.

Published it? Check that it is live and valid. DNS changes can take a few minutes to an hour to appear.

Before you publish

A domain must have exactly one SPF record. If you already have a TXT record starting with v=spf1, edit it rather than adding a new one. Two SPF records make SPF fail for every message.

List every service that sends as you: your mailbox provider, newsletter tool, CRM, help desk, invoicing app and website contact form. Anything you miss fails SPF, and once DMARC is enforced, its mail goes to spam.

Lookup counts here are typical values for each provider and can change when they edit their records. After publishing, run the SPF checker, which counts the real total.

Know the day it breaks

Records that are right today get edited, overwritten or dropped in a DNS move. SenderBeacon re-checks twice a day and emails you in plain English. From $9/month, 14-day free trial, no card.

Start free trial

Questions

Where do I add the SPF record?

In your DNS host (often your domain registrar or Cloudflare), as a TXT record with host "@" or blank, meaning the root of the domain.

Can I have two SPF records if they are for different services?

No. Merge all services into one record. Receivers treat two v=spf1 records as a permanent error.

Should the record end in ~all or -all?

Use ~all while you are still confirming every sender. Once DMARC reports show all real mail passing, -all is fine. DMARC makes the final decision either way.