PC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteSome links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
SPF (Sender Policy Framework) is an email-authentication standard that lets a domain publish, in DNS, which servers may send mail using that domain in the SMTP HELO or MAIL FROM identities. A receiving mail system checks the connecting host against that policy. SPF is an authorization check—not proof that the person or organization shown in the visible From: header sent the message.
SPF is most useful when deployed with DKIM and DMARC, because those standards address message signatures and alignment with the visible From domain.
What does an SPF record do?
An SPF policy is published as a DNS TXT record for the domain whose SMTP identity is being authorized. During delivery, the recipient evaluates the sender’s IP address against mechanisms in that policy. RFC 7208 defines the protocol as one by which administrative management domains can authorize hosts to use their names in the MAIL FROM or HELO identities: RFC 7208.
The SMTP envelope and the visible From header are separate. A message can pass SPF for an envelope domain while displaying a different visible From domain. DMARC checks whether SPF or DKIM authentication aligns with that visible From domain, so an SPF pass alone does not establish that the displayed sender is genuine.
#1 Best Overall
How SPF evaluation works
- The receiving server identifies the connecting IP address and the applicable
HELOandMAIL FROMidentities. - It retrieves the domain’s SPF policy from DNS.
- It evaluates the policy’s mechanisms, such as authorized IP addresses or included provider policies.
- It returns a result that the receiver can use alongside DKIM and DMARC processing.
SPF results and what they mean
| Result | Meaning |
|---|---|
pass |
The checked identity’s policy authorizes the client host. |
fail |
The policy explicitly says the client is not authorized. |
softfail |
The policy considers the client probably unauthorized but does not make an absolute assertion. |
neutral |
The policy makes no authorization decision. |
none |
No applicable SPF policy was found. |
temperror |
A temporary DNS or evaluation problem prevented a definitive result. |
permerror |
The policy is permanently invalid or cannot be correctly interpreted, including an excessive DNS-query count. |
A failed result does not automatically mean a message is malicious. A legitimate service can fail when its sending host was omitted, while DNS outages or a malformed record can produce errors.
How do I set up an SPF record?
SPF belongs in the DNS controls for the domain used by your outbound mail. Inventory every service that sends with that domain before editing the record: hosted mail, web servers, contact forms, gateways, ticketing systems and third-party marketing platforms can all be separate senders.
- List all senders. Confirm the envelope domains and sending services used by each application.
- Obtain each provider’s SPF mechanism. Providers commonly publish an
include:value or specify IP addresses. Use the provider’s current documentation rather than guessing. - Combine senders in the applicable policy. Do not create a second SPF record for the same domain without checking the existing DNS policy; update the one policy to cover all authorized services.
- Publish a DNS TXT record. Enter it at the DNS host for the exact domain being authorized. Google documents the general workflow—identify senders, prepare the value and publish it—in its Google Workspace SPF setup guide.
- Verify real mail. Inspect authentication results in message headers or provider reports after DNS changes, and confirm that each legitimate sender passes.
For a domain that sends only through Google Workspace, Google’s guide gives v=spf1 include:_spf.google.com ~all as an example. It is not a universal record: a domain using any additional sender must add that service’s authorized mechanism. Google says SPF authentication can take up to 48 hours to start working after publication; that is operational guidance from Google, not a guaranteed propagation time for every DNS provider.
What does the SPF DNS lookup limit mean?
One SPF evaluation may use no more than 10 DNS-query-causing terms, as required by RFC 7208. Mechanisms and modifiers such as include, a, mx, ptr, exists and redirects can trigger lookups. Nested includes count too, so the relevant total is the expanded policy—not merely the number of words visible in your top-level TXT record. Exceeding the limit must produce permerror under RFC 7208.
Google’s troubleshooting guidance explains that an over-limit or otherwise malformed policy can cause legitimate mail to fail SPF: Troubleshoot SPF issues. Reduce unnecessary mechanisms, remove obsolete senders and use provider-supported consolidation where available; do not solve the problem by publishing multiple SPF records.
What is the difference between SPF, DKIM and DMARC?
| Standard | What it evaluates | Connection to visible From |
|---|---|---|
| SPF | Whether the connecting host is authorized for the SMTP HELO or MAIL FROM identity under DNS policy. |
Not direct. The envelope identity can differ from the visible From domain, and forwarding can change the connecting host. |
| DKIM | A cryptographic signature that lets the receiver verify signed message content and associate it with the signing domain. | The signing domain can be evaluated for alignment with the visible From domain by DMARC. |
| DMARC | Policy and reporting for whether SPF or DKIM authentication aligns with the visible From domain. | Yes. DMARC is specifically concerned with alignment of an authenticated domain and the visible From domain; see RFC 9989. |
These standards complement one another. SPF authorizes infrastructure, DKIM supplies tamper-evident signing, and DMARC applies alignment, policy and reporting. Google’s sender guidance recommends SPF or DKIM for all senders to personal Gmail accounts. For senders exceeding 5,000 messages per day to Gmail accounts, Google’s requirements effective February 1, 2024 call for SPF, DKIM and DMARC: Gmail email sender guidelines. Those are Google’s provider rules, not a universal Internet threshold.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Maintaining SPF after setup
- Review the sender inventory whenever you add, remove or replace a mail service.
- Keep one authoritative SPF policy for each domain and check for stale includes.
- Monitor headers and authentication reports for unexpected failures.
- Investigate DNS errors separately from unauthorized-host results.
- Recheck the 10-query budget after every provider change, including nested includes.
SPF is therefore best treated as an ongoing DNS policy, not a one-time switch. Its value depends on an accurate list of current senders and on pairing it with DKIM and DMARC.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

