SPF record generator

Pick your mail providers, add your own servers and copy a valid SPF record. The 10-lookup limit and the 255-character string length are checked as you type. Nothing is sent to a server.

Who sends mail for your domain?

Mail providers

Only providers whose include value is documented by the provider itself are offered as presets.

One host per line, as given in your provider's documentation, for example _spf.example.net. Zarfio and other providers: paste the include host shown in your account.

One per line, for example 192.0.2.10 or 198.51.100.0/24.

One per line, for example 2001:db8::/32.

Mail from every other source

Your SPF record

Host / name
@ (the domain itself)
Type
TXT
Value
v=spf1 ~all

DNS-lookup mechanisms in this record: 0 of 10

include, a and mx cost one lookup each. Lookups inside the included records count as well and are not visible here, so check the published record.

Length: 11 characters

This record authorizes nobody. That is right for a domain that sends no mail (use -all); otherwise add your senders.
A domain must have exactly one SPF record. If one exists already, replace it instead of adding a second.

Check the published record with the SPF checker →

This generator runs in your browser. Nothing you type is sent anywhere.

How an SPF record is put together

An SPF record is one TXT record on the domain that lists who may send mail using that domain in the envelope sender. It starts with v=spf1, continues with mechanisms that are read from left to right, and ends with an all term that says what to do with everyone else. include:_spf.google.com authorizes whatever Google lists in its own record; ip4: and ip6: authorize addresses or ranges directly; a and mx authorize the addresses behind the domain's own A and MX records.

A domain must have exactly one SPF record. If you already have one, edit it instead of adding a second: two records are an error and receivers treat the result as a permanent failure.

~all or -all

~all (softfail) says mail from other sources is probably not legitimate; receivers usually accept it and weigh it. -all (fail) says it is not legitimate, full stop. With DMARC in place the difference matters less than it used to, because DMARC decides what happens to mail that fails. While you are still discovering which systems send for you, ~all is the careful choice; a domain that sends no mail at all should publish v=spf1 -all.

The two limits that break SPF records

Evaluating a record may cause at most 10 DNS lookups. Every include, a, mx, exists and redirect costs one, and the lookups inside an included record count as well. The generator counts the mechanisms in your record; the providers' own records add to that, so stay well below ten and verify the published record with the SPF checker. ip4 and ip6 cost nothing.

A single string inside a TXT record can hold 255 characters. Longer records are valid if they are split into several quoted strings, which the generator does for you; many DNS control panels also do it automatically.

How to use this tool

  1. Select your senders. Tick the mail providers you use and add include hosts, IPv4 and IPv6 addresses of your own servers.
  2. Choose ~all or -all. Pick how receivers should treat mail from sources that are not listed, and watch the lookup counter stay below 10.
  3. Copy and publish. Copy the record, publish it as a TXT record on the domain itself and verify it with the SPF checker.

Command line equivalent

The same check from a terminal. The commands use example.com: replace it with your own name.

  • Record that is published nowdig example.com TXT +short | grep -i "v=spf1"
  • Windowsnslookup -type=TXT example.com

The generator itself needs no command: it only builds text. These commands show what is published after you add the record.

FAQ

How do I create an SPF record?

Select the services that send mail for your domain, add the IP addresses of your own mail servers, choose ~all or -all, copy the value and publish it as a TXT record on the domain itself (host @).

What is the SPF record for Google Workspace or Microsoft 365?

Google Workspace documents include:_spf.google.com and Microsoft 365 documents include:spf.protection.outlook.com. A domain that uses only one of them publishes, for example, v=spf1 include:_spf.google.com ~all.

What happens above 10 DNS lookups?

The evaluation stops with a permanent error and receivers treat SPF as failed for every message, including legitimate ones. Remove includes you no longer use, or replace includes with ip4/ip6 ranges that you control.

Does this tool publish anything or contact my DNS?

No. It runs in your browser and only builds text. You publish the record at your DNS host, then check it with the SPF checker.

My provider is not in the list. What do I do?

Look up the include host in your provider's own documentation and type it into the include field. We only offer presets for values we can point to in the provider's documentation.