SPF Guide

By Abdul Sami, GTM Engineer · 6 min read · Last updated

SPF (Sender Policy Framework) is a DNS TXT record listing which servers may send email for your domain. A valid setup: exactly one record, under 10 DNS lookups, ending in -all. Example: v=spf1 include:_spf.google.com -all.

Record anatomy

v=spf1 declares the version. Mechanisms follow: include: (authorize another domain's senders), ip4: (a specific address), a and mx (your own hosts). The record ends with an all mechanism defining the default policy.

The all policy

MechanismMeaningUse
-allHard fail reject unlisted sendersRecommended end state
~allSoft fail mark but acceptDuring migration
+allAuthorize everyoneNever dangerous
?allNeutralPointless; pick a stance

The 10-lookup limit

SPF evaluation may do at most 10 DNS lookups. Each include counts, and nested includes count too. Exceeding it returns PermError mail fails authentication. Audit with the SPF Checker; flatten or remove unused senders to get back under.

The two-record trap

Two TXT records starting with v=spf1 make SPF invalid entirely. When adding a sender, merge its include into the existing record never add a second one.

FAQ

How do I check my domain's SPF record?
Use the SPF Checker on this site, or query TXT records for your domain in any DNS tool and look for the entry starting v=spf1.
Does SPF apply to subdomains?
No each (sub)domain needs its own record. Sending from mail.example.com requires an SPF record on mail.example.com.
Is SPF enough to stop spoofing?
No. SPF checks the envelope sender and breaks on forwarding. Pair it with DKIM and enforce with DMARC for real protection.
AS

Abdul Sami

GTM Engineer, DFY GTM Systems

7+ years building outbound systems for B2B companies across the US, UK, Australia, and DACH. Specializes in Clay workflows, cold email infrastructure, intent-based lead sourcing, and deliverability.

Rather have it built for you?

One team builds and runs the whole system in your accounts. Live in 10 days.

Book a strategy call