Rankite
ServicesResultsToolsTeamAboutBlogCareersContactFree SEO Audit
Free tool

SPF Record Generator: Build a Valid SPF DNS Record

Select who is allowed to send mail for your domain, then copy a ready-to-publish SPF TXT record, free.

Home / Tools / SPF Record Generator
Your SPF DNS record
Record type
TXT
DNS lookups used
0 / 10

Built by Rankite, the SEO team behind Swordfish AI's +400% revenue and Zluri's +45% organic growth. See the case studies

An SPF record is a DNS TXT record that lists exactly which mail servers are allowed to send email claiming to be from your domain. It is one of the oldest and simplest email authentication standards, and receiving servers like Gmail and Outlook check it on almost every message they process. Getting it right is a prerequisite for good deliverability, and a broken or missing SPF record is one of the most common reasons legitimate marketing and transactional email lands in spam.

How an SPF record actually works

When a mail server receives a message, it looks up the SPF TXT record for the domain in the message's envelope sender address, then checks whether the server that actually sent the message is listed. Each sending service, such as Google Workspace, Microsoft 365 or a marketing platform like Mailchimp, publishes its own set of servers behind an include: mechanism, which is why this tool lets you add each provider you actually use rather than typing raw IP addresses by hand. Everything else, mx, a, ip4 and ip6, lets you list your own servers directly.

The 10 DNS lookup limit

RFC 7208, the SPF specification, caps a record at 10 DNS lookups per check, counting every include, a, mx, ptr, exists and redirect mechanism, including the lookups nested inside another provider's own included record. Cross that limit and the entire SPF check is required to fail as a permanent error, regardless of whether the actual sender was legitimate. This tool counts lookups as you add senders so you can see how close you are before you publish.

Choosing the right -all qualifier

The final mechanism in an SPF record tells receivers what to do with mail from a source that is not listed. Start a new setup cautiously with ~all, soft fail, which lets mail through while flagging anything unlisted, so you can catch a missed sending source in your logs before it gets blocked. Once you have confirmed every legitimate sender is listed, move to -all, hard fail, which is what stops attackers from spoofing your domain outright.

Related articles

FAQ

SPF Record Generator: questions, answered

What is an SPF record?
SPF, short for Sender Policy Framework, is a DNS TXT record that lists which mail servers are allowed to send email on behalf of your domain. Receiving mail servers check this list, and if a message claims to be from your domain but was sent from a server that is not on it, SPF fails, which makes the message more likely to be marked as spam or rejected.
What is the difference between -all, ~all and ?all?
These are qualifiers that tell receiving servers what to do with mail from a source not listed in your SPF record. -all means hard fail, reject it. ~all means soft fail, usually deliver it but flag it as suspicious. ?all means neutral, treat it as if there were no policy at all. Most domains should end their record with -all once every legitimate sending source is confirmed and listed.
What is the 10 DNS lookup limit?
The SPF standard, RFC 7208, caps the number of DNS lookups a single SPF check can trigger at 10, counting each include, a, mx, ptr, exists and redirect mechanism. Go over that limit and receiving servers are required to treat the whole record as a permanent error, which can break delivery entirely, so keep the list of included senders as short as possible.
Can I have more than one SPF record for my domain?
No. A domain can only have one SPF record, meaning one TXT record starting with v=spf1. If two exist, mail servers cannot reliably determine which one applies, and validation typically fails outright. If you use multiple email services, they all need to be combined into this single record.
Where do I publish an SPF record?
Add it as a TXT record at the root of your domain, for example example.com rather than a subdomain, in your DNS provider's dashboard. Paste the value this tool generates exactly as shown, save, and allow up to a few hours for it to propagate before testing.
Do I still need DKIM and DMARC if I have SPF?
Yes. SPF only checks which servers are authorized to send, it does not verify that a message was not altered in transit, which is what DKIM does, and it has no enforcement policy of its own, which is what DMARC adds on top. All three work together for real protection against spoofing.

More free tools

Let's grow

Ready to own page one?

Get a free, no-obligation SEO audit and a 30-minute strategy session. We'll show you exactly where the growth is hiding.

Book your free audit Explore services
Get in touch

Tell us about your project

Fill out the form and we'll get back to you within one business day. Prefer email? Write to us directly at contact@rankite.com.

Or copy our email and write to us directly: contact@rankite.com