How an SPF record is put together
An SPF record is one TXT record on the domain that lists who may send mail using that domain in the envelope sender. It starts with v=spf1, continues with mechanisms that are read from left to right, and ends with an all term that says what to do with everyone else. include:_spf.google.com authorizes whatever Google lists in its own record; ip4: and ip6: authorize addresses or ranges directly; a and mx authorize the addresses behind the domain's own A and MX records.
A domain must have exactly one SPF record. If you already have one, edit it instead of adding a second: two records are an error and receivers treat the result as a permanent failure.
~all or -all
~all (softfail) says mail from other sources is probably not legitimate; receivers usually accept it and weigh it. -all (fail) says it is not legitimate, full stop. With DMARC in place the difference matters less than it used to, because DMARC decides what happens to mail that fails. While you are still discovering which systems send for you, ~all is the careful choice; a domain that sends no mail at all should publish v=spf1 -all.
The two limits that break SPF records
Evaluating a record may cause at most 10 DNS lookups. Every include, a, mx, exists and redirect costs one, and the lookups inside an included record count as well. The generator counts the mechanisms in your record; the providers' own records add to that, so stay well below ten and verify the published record with the SPF checker. ip4 and ip6 cost nothing.
A single string inside a TXT record can hold 255 characters. Longer records are valid if they are split into several quoted strings, which the generator does for you; many DNS control panels also do it automatically.