Free SPF Record Generator Build a Valid SPF Record

Build a valid SPF record without memorizing syntax. Add your sending services as includes, any dedicated IPs, pick an enforcement policy, and copy the generated record straight into your DNS as a TXT entry.

How this check works

  1. 01

    Enter include domains (e.g. _spf.google.com for Google Workspace), IPv4 addresses, and whether your MX/A hosts also send.

  2. 02

    Choose the closing policy: -all (strict) or ~all (soft fail).

  3. 03

    The generator assembles the record, validates the syntax, and warns if you approach the 10-lookup budget.

How to fix common problems

Where does the record go?

Create a TXT record at your root domain (@) with the generated value. One SPF record per domain merge, never duplicate.

Subdomains need their own

SPF does not inherit to subdomains. If you send from mail.example.com, publish a record on that subdomain too.

Example

Google Workspace + a dedicated IP → v=spf1 include:_spf.google.com ip4:203.0.113.10 -all

FAQ

Where do I publish the SPF record?
In your DNS provider (Cloudflare, GoDaddy, etc.) as a TXT record with host @ and the generated value.
How do I find my ESP's include?
Every reputable ESP documents it: Google uses _spf.google.com, Microsoft 365 uses spf.protection.outlook.com, and so on.
Does SPF alone stop spoofing?
No SPF only covers the envelope sender and breaks on forwarding. Pair it with DKIM and enforce with DMARC.

Want this handled end-to-end?

We build and run the whole outbound system infrastructure, lists, and copy live in 10 days.

See the cold email system