What is SPF? Sender Policy Framework explained

SPF (Sender Policy Framework) is a DNS record that lists which servers are allowed to send email for a domain.

A domain publishes its SPF policy as a TXT record that starts with v=spf1. A receiving server compares the IP address of the server that delivered the message with that list. If the IP is not authorized, the message fails SPF.

A typical record looks like v=spf1 include:_spf.google.com include:mailgun.org ~all: mail from Google Workspace and Mailgun is allowed, and ~all marks everything else as a soft fail (-all would be a hard fail).

Common mistakes: publishing two SPF records for the same domain (only one is allowed), forgetting a sending service you added later, and exceeding the limit of 10 DNS lookups that the include entries add up to.

With Easy Email Verification

SPF is one of the three authentication checks, with DKIM and DMARC, that mailbox providers now expect. The email checker domain report shows a domain's SPF and DMARC records.

Check an address for freeClean a whole list

Related

  • DKIM (DomainKeys Identified Mail): DKIM (DomainKeys Identified Mail) adds a digital signature to each email so the receiver can check that it was sent by the domain and not changed on the way.
  • DMARC: DMARC (Domain-based Message Authentication, Reporting and Conformance) is a DNS policy that tells receivers what to do with email that fails authentication for your domain, and asks them to send you reports.
  • Sender reputation: Sender reputation is how trustworthy mailbox providers consider your sending domain and IP address, based on how your past email was received.
  • All glossary terms

By using this website, you automatically accept that we use cookies.