
An SPF record is a single line in your domain’s DNS that lists which mail servers are allowed to send email on behalf of your business. SPF stands for Sender Policy Framework, and it is the first of the three email authentication standards every organization should have in place. When a receiving server gets a message claiming to be from your domain, it checks your SPF record to confirm the sending server is authorized. If it is not, the message is flagged as suspicious.
This guide covers what an SPF record is, why your business needs one, how to read the syntax, and the common mistakes that quietly break email delivery. It is part of our larger overview on email authentication with SPF, DKIM, and DMARC.
What an SPF Record Does
Think of your SPF record as a guest list for a private event. Only the servers named on the list are allowed to send mail using your domain name. Your email platform, your CRM, your invoicing tool, and your marketing service each send mail as you, so each one needs to appear on that list. When a message arrives, the recipient’s mail server compares the sending server’s address against your published record. A match means the server is authorized; no match means the message may be a forgery.
Why Your Business Needs SPF
Without valid SPF, two things happen. First, your legitimate email is more likely to land in the spam folder, because receiving servers cannot confirm you are who you say you are. Second, your domain becomes an easy target for spoofing, where a scammer sends phishing emails that appear to come from your company. A correctly configured SPF setup reduces both problems and is a prerequisite for DMARC, the policy layer that ties everything together.
Since Google and Yahoo tightened their sender rules in 2024, SPF is no longer a nice-to-have. Bulk senders without proper authentication risk having their mail rejected outright by major providers.
How to Read an SPF Record
An SPF record is a TXT record in your DNS that begins with v=spf1. A typical record for a business using Microsoft 365 and Google Workspace-style services might look like this:
v=spf1 include:spf.protection.outlook.com include:_spf.google.com ~all
Here is what each part means:
v=spf1declares the version of the SPF standard.include:pulls in the authorized servers of a mail provider you use, such as Microsoft 365.~allis the enforcement rule at the end.~allmeans “soft fail” (mark but usually still deliver), while-allmeans “hard fail” (reject anything not listed).
Every service that sends mail as you must be represented in the record, or that service’s mail may fail the SPF check.
Common SPF Mistakes to Avoid
A few errors account for most SPF problems:
- Too many DNS lookups. The SPF standard limits a record to 10 DNS lookups. Businesses that use many email services can exceed this and cause the whole record to fail.
- More than one SPF record. A domain may publish only one SPF record. Two records is an error that breaks authentication.
- Forgetting a sending service. Adding a new marketing tool or invoicing platform without updating the record means that service’s mail may be flagged.
- Using the wrong enforcement rule. Jumping straight to
-allbefore confirming every legitimate sender is listed can block your own mail.
Because SPF alone breaks when mail is forwarded, it should always be paired with DKIM and enforced with DMARC.
Let ABS Handle Your Email Authentication
Editing DNS is easy to get wrong, and a broken record can silently send your invoices and client emails to spam. Advanced Business Systems configures and monitors SPF, DKIM, and DMARC for businesses in Tallahassee, Thomasville, and across North Florida and South Georgia as part of our managed IT services. Call ABS at (850) 222-2308 or contact us to review your email setup.
For technical reference, see the official SPF specification (RFC 7208) and Google’s SPF guidance.
Frequently Asked Questions
Can I have more than one SPF record?
No. A domain must have exactly one SPF record. If you use multiple mail services, combine them into a single record using multiple include: statements rather than publishing separate records.
What is the difference between ~all and -all?
Both appear at the end of an SPF record. ~all is a soft fail that marks unauthorized mail as suspicious but often still delivers it. -all is a hard fail that instructs servers to reject unlisted mail. Move to -all only after confirming every legitimate sender is included.
Does an SPF record stop spoofing on its own?
Not completely. SPF checks the sending server but does not survive email forwarding and does not tell a receiving server what to do on failure. Pairing it with DKIM and DMARC provides real anti-spoofing protection.
How do I know if my SPF record is broken?
Signs include legitimate mail landing in spam, a specific service’s emails not arriving, or DMARC reports showing SPF failures. A managed IT provider can audit the record and confirm every sender is authorized.
