Free tool · live DNS lookup count
SPF record generator
Tick the services that send email for your domain. The SPF record generator writes one valid record, counts its DNS lookups against the limit of 10 and shows where to add it.
Your SPF record
example.com TXT "v=spf1 include:_spf.google.com ~all"
SPF includes for common email services
Each service that sends mail as your domain publishes its servers in its own SPF record, and you pull it into yours with include:. These are the values from each provider’s documentation:
| Service | SPF include | Note | Provider docs |
|---|---|---|---|
| Google Workspace | include:_spf.google.com | Google recommends ~all. | Docs |
| Microsoft 365 | include:spf.protection.outlook.com | Microsoft recommends -all. GCC High and DoD use spf.protection.office365.us. | Docs |
| Zoho Mail | include:zohomail.com | Zoho suggests one.zoho.com instead if you send from several Zoho apps. | Docs |
| Proton Mail | include:_spf.protonmail.ch | Docs | |
| Fastmail | include:spf.messagingengine.com | Fastmail's own example ends with ?all. | Docs |
| iCloud+ (custom domain) | include:icloud.com | Docs | |
| Hostinger Email | include:_spf.mail.hostinger.com | Docs | |
| SendGrid | include:sendgrid.net | Not needed if you set up Domain Authentication with automated security (CNAME records). | Docs |
| Mailgun | include:mailgun.org | Mailgun asks for it on the domain you verified with them, often a subdomain. | Docs |
| Mailjet | include:spf.mailjet.com | Docs | |
| Zendesk | include:mail.zendesk.com | Zendesk's own example ends with -all. | Docs |
| Freshdesk | include:email.freshdesk.com | Docs |
Values checked against each provider's documentation on October 9, 2026. Providers change their setup now and then, so follow their current instructions if they differ.
Some services don’t need an include on your domain because they send with their own bounce (Return-Path) domain, or with a subdomain you point to them with a CNAME record. SPF checks that domain, not yours. Postmark, Brevo and Mailchimp Transactional work this way; follow their domain setup instead. Amazon SES needs SPF only if you use a custom MAIL FROM domain, and then the record v=spf1 include:amazonses.com ~all goes on that subdomain (for example bounce.example.com), not on your main domain.
How to add the SPF record at your DNS host
Add one TXT record on the domain itself. If a TXT record starting with v=spf1 already exists, edit it instead: a second SPF record breaks both. Other TXT records, such as site verification codes, stay as they are.
| DNS host | Name field | Enter | Value field | Note |
|---|---|---|---|---|
| Cloudflare | Name | @ | Content | |
| GoDaddy | Name | @ | Value | |
| Namecheap | Host | @ | Value | |
| Squarespace Domains | Name | @ | Data | |
| Amazon Route 53 | Record name | leave empty | Value | Put the value in double quotes; split values over 255 characters into several quoted strings. |
DNS changes are usually visible within an hour. Then run the SPF checker to confirm what receivers see.
SPF record examples
| Who sends for the domain | SPF record |
|---|---|
| Google Workspace only | v=spf1 include:_spf.google.com ~all |
| Microsoft 365 only | v=spf1 include:spf.protection.outlook.com -all |
| Google Workspace and Mailgun | v=spf1 include:_spf.google.com include:mailgun.org ~all |
| Microsoft 365 and Zendesk | v=spf1 include:spf.protection.outlook.com include:mail.zendesk.com -all |
| Your own mail server and Zoho Mail | v=spf1 ip4:203.0.113.10 include:zohomail.com ~all |
| Nobody: the domain sends no email | v=spf1 -all |
Receivers read the record from left to right and stop at the first match, so put ip4 and ip6 ranges first: they need no DNS lookup.
The 10-lookup limit, and how to stay under it
RFC 7208 caps the DNS lookups a receiver makes for one SPF check at 10. include, a, mx, ptr, exists and redirect count, and so does every lookup inside the records you include. A check that needs an 11th lookup ends with a permanent error (permerror), which DMARC counts as an SPF failure. Which senders break depends on where they sit in the record, so the failures are often partial and easy to miss. An include that points to a domain without an SPF record ends the check the same way, and receivers may also give up after more than two lookups that find nothing at all.
The count changes when providers change their own records. Google’s _spf.google.com, for example, currently lists its IP ranges directly, so it costs one lookup, while other providers nest several includes. That is why the generator resolves the includes live instead of using a fixed table.
If you are over the limit:
- Remove services you no longer use. Old newsletter tools and CRMs are the usual suspects.
- Check whether a service needs the include at all. Many senders now authenticate with their own Return-Path domain and DKIM, as described above.
- Move a sender to a subdomain (for example
news.example.comwith its own SPF record), so its includes don’t count against the main domain. - Replace an include with the IP ranges it lists (“flattening”). This saves lookups but breaks silently when the provider changes its servers, so only do it for ranges you control.
~all, -all or ?all
The all mechanism at the end decides what happens to mail from servers that are not listed:
~all(softfail): accept the mail but treat it as suspicious. Google recommends it for Google Workspace.-all(fail): ask receivers to reject the mail. Microsoft recommends it for Microsoft 365, together with DKIM and DMARC.?all(neutral): say nothing about other servers. Only useful while you test.+all: lets any server on the internet pass SPF for your domain. Never use it.
SPF on its own does not protect the address people see in the From header. That is the job of DMARC, which checks that SPF or DKIM passed for the same domain as the From address. Once SPF is in place, create a DMARC record with the DMARC generator and check DKIM with the DKIM checker.
Frequently asked questions
How do I create an SPF record?
Can I have two SPF records?
Should I use ~all or -all?
What is the SPF 10 lookup limit?
Where do I add the SPF record?
Does a domain that sends no email need SPF?
Email validation API
Validate emails in your app
emailvalidation.io checks syntax, MX records and the mailbox over SMTP, flags disposable, role and free addresses and returns a quality score, in one request.
/v1/info Email validation API Read the documentation
100 free validations every month. No credit card required.
GET https://api.emailvalidation.io/v1/info?
{
"email": "support@emailvalidation.io",
"user": "support",
"tag": "",
"domain": "emailvalidation.io",
"format_valid": true,
"mx_found": true,
"smtp_check": true,
"catch_all": null,
"role": true,
"disposable": false,
"free": false,
"score": 0.64,
"state": "deliverable",
"reason": "valid_mailbox",
"did_you_mean": ""
}