Free tool · live DNS lookup count

SPF record generator

Tick the services that send email for your domain. The SPF record generator writes one valid record, counts its DNS lookups against the limit of 10 and shows where to add it.

A domain can have only one SPF record. Load the one you have and add to it.

Where your mailboxes are

The service your team sends normal email from.

Services that send email as you

Newsletters, transactional email, help desk. Tick a service only if its setup guide asks you to add an include to your SPF record.

Your own servers and other services

IPv4 or IPv6, with an optional /prefix. Separate with spaces or new lines. IP addresses cost no DNS lookups.

Copy the include value from the service's documentation, for example _spf.example-crm.com.

Mail from servers not on the list

The record is built in your browser. Nothing you type here is sent to us.

Your SPF record

example.com  TXT  "v=spf1 include:_spf.google.com ~all"

SPF includes for common email services

Each service that sends mail as your domain publishes its servers in its own SPF record, and you pull it into yours with include:. These are the values from each provider’s documentation:

ServiceSPF includeNoteProvider docs
Google Workspaceinclude:_spf.google.comGoogle recommends ~all.Docs
Microsoft 365include:spf.protection.outlook.comMicrosoft recommends -all. GCC High and DoD use spf.protection.office365.us.Docs
Zoho Mailinclude:zohomail.comZoho suggests one.zoho.com instead if you send from several Zoho apps.Docs
Proton Mailinclude:_spf.protonmail.chDocs
Fastmailinclude:spf.messagingengine.comFastmail's own example ends with ?all.Docs
iCloud+ (custom domain)include:icloud.comDocs
Hostinger Emailinclude:_spf.mail.hostinger.comDocs
SendGridinclude:sendgrid.netNot needed if you set up Domain Authentication with automated security (CNAME records).Docs
Mailguninclude:mailgun.orgMailgun asks for it on the domain you verified with them, often a subdomain.Docs
Mailjetinclude:spf.mailjet.comDocs
Zendeskinclude:mail.zendesk.comZendesk's own example ends with -all.Docs
Freshdeskinclude:email.freshdesk.comDocs

Values checked against each provider's documentation on October 9, 2026. Providers change their setup now and then, so follow their current instructions if they differ.

Some services don’t need an include on your domain because they send with their own bounce (Return-Path) domain, or with a subdomain you point to them with a CNAME record. SPF checks that domain, not yours. Postmark, Brevo and Mailchimp Transactional work this way; follow their domain setup instead. Amazon SES needs SPF only if you use a custom MAIL FROM domain, and then the record v=spf1 include:amazonses.com ~all goes on that subdomain (for example bounce.example.com), not on your main domain.

How to add the SPF record at your DNS host

Add one TXT record on the domain itself. If a TXT record starting with v=spf1 already exists, edit it instead: a second SPF record breaks both. Other TXT records, such as site verification codes, stay as they are.

DNS hostName fieldEnterValue fieldNote
CloudflareName@Content
GoDaddyName@Value
NamecheapHost@Value
Squarespace DomainsName@Data
Amazon Route 53Record nameleave emptyValuePut the value in double quotes; split values over 255 characters into several quoted strings.

DNS changes are usually visible within an hour. Then run the SPF checker to confirm what receivers see.

SPF record examples

Who sends for the domainSPF record
Google Workspace onlyv=spf1 include:_spf.google.com ~all
Microsoft 365 onlyv=spf1 include:spf.protection.outlook.com -all
Google Workspace and Mailgunv=spf1 include:_spf.google.com include:mailgun.org ~all
Microsoft 365 and Zendeskv=spf1 include:spf.protection.outlook.com include:mail.zendesk.com -all
Your own mail server and Zoho Mailv=spf1 ip4:203.0.113.10 include:zohomail.com ~all
Nobody: the domain sends no emailv=spf1 -all

Receivers read the record from left to right and stop at the first match, so put ip4 and ip6 ranges first: they need no DNS lookup.

The 10-lookup limit, and how to stay under it

RFC 7208 caps the DNS lookups a receiver makes for one SPF check at 10. include, a, mx, ptr, exists and redirect count, and so does every lookup inside the records you include. A check that needs an 11th lookup ends with a permanent error (permerror), which DMARC counts as an SPF failure. Which senders break depends on where they sit in the record, so the failures are often partial and easy to miss. An include that points to a domain without an SPF record ends the check the same way, and receivers may also give up after more than two lookups that find nothing at all.

The count changes when providers change their own records. Google’s _spf.google.com, for example, currently lists its IP ranges directly, so it costs one lookup, while other providers nest several includes. That is why the generator resolves the includes live instead of using a fixed table.

If you are over the limit:

  1. Remove services you no longer use. Old newsletter tools and CRMs are the usual suspects.
  2. Check whether a service needs the include at all. Many senders now authenticate with their own Return-Path domain and DKIM, as described above.
  3. Move a sender to a subdomain (for example news.example.com with its own SPF record), so its includes don’t count against the main domain.
  4. Replace an include with the IP ranges it lists (“flattening”). This saves lookups but breaks silently when the provider changes its servers, so only do it for ranges you control.

~all, -all or ?all

The all mechanism at the end decides what happens to mail from servers that are not listed:

  • ~all (softfail): accept the mail but treat it as suspicious. Google recommends it for Google Workspace.
  • -all (fail): ask receivers to reject the mail. Microsoft recommends it for Microsoft 365, together with DKIM and DMARC.
  • ?all (neutral): say nothing about other servers. Only useful while you test.
  • +all: lets any server on the internet pass SPF for your domain. Never use it.

SPF on its own does not protect the address people see in the From header. That is the job of DMARC, which checks that SPF or DKIM passed for the same domain as the From address. Once SPF is in place, create a DMARC record with the DMARC generator and check DKIM with the DKIM checker.

Frequently asked questions

How do I create an SPF record?

List every service that sends email with your domain, take each one's include value (or your servers' IP addresses), end with ~all or -all, and publish the result as one TXT record on your domain. The generator above writes the record and counts its DNS lookups.

Can I have two SPF records?

No. If a domain publishes two records that start with v=spf1, SPF returns a permanent error and fails for all of its mail (RFC 7208). Merge them: one v=spf1 at the start, every mechanism in the middle, one all at the end. Click “Load current record” in the generator to start from the record you have.

Should I use ~all or -all?

Both say that servers not on the list are not allowed. -all asks receivers to reject such mail, ~all asks them to accept it but treat it as suspicious. Google recommends ~all for Google Workspace, Microsoft recommends -all for Microsoft 365. Never use +all: it allows every server on the internet.

What is the SPF 10 lookup limit?

Checking an SPF record may take at most 10 DNS lookups. include, a, mx, ptr, exists and redirect cost one each, plus the lookups inside every included record; ip4, ip6 and all cost none. A check that needs an 11th lookup ends with a permanent error, which counts as an SPF failure. The counter in the generator adds them up live.

Where do I add the SPF record?

At the DNS host of your domain, as a TXT record on the domain itself. Most DNS hosts write that as @ in the name field; some want the field left empty.

Does a domain that sends no email need SPF?

Yes. Publish v=spf1 -all, plus a DMARC record with p=reject, so nobody can send mail that passes as your domain.

Email validation API

Validate emails in your app

emailvalidation.io checks syntax, MX records and the mailbox over SMTP, flags disposable, role and free addresses and returns a quality score, in one request.

/v1/info Email validation API Read the documentation

100 free validations every month. No credit card required.

GET https://api.emailvalidation.io/v1/info?email=support@emailvalidation.io

{
  "email": "support@emailvalidation.io",
  "user": "support",
  "tag": "",
  "domain": "emailvalidation.io",
  "format_valid": true,
  "mx_found": true,
  "smtp_check": true,
  "catch_all": null,
  "role": true,
  "disposable": false,
  "free": false,
  "score": 0.64,
  "state": "deliverable",
  "reason": "valid_mailbox",
  "did_you_mean": ""
}

Free email tools

Start using our email validation software today!

Get 100 validations per month for free