Multiple SPF records: how to merge them
Two SPF records on one domain make SPF fail for every email (a permerror). How to merge them into one record without losing a sender.
By the Domain Health Hub team · Updated
- A domain may have only one TXT record starting v=spf1. With two or more, SPF returns a permanent error.
- It usually happens when a new service's set-up guide says 'add this SPF record' and someone does.
- Merge every entry into one record, keep one all at the end, and delete the others.
What it means
We found more than one TXT record at the domain root starting v=spf1. The SPF standard (RFC 7208, section 4.5) allows exactly one. When a receiver finds two, it doesn't pick one: it stops and returns a permanent error (permerror).
Why it matters
A permerror means SPF fails for every message from the domain, the genuine ones included. Many receivers treat that as a fail, and DMARC can no longer pass on SPF, so every email depends on DKIM. It's one of the most common SPF problems, because services' set-up guides often say “add this SPF record” when they mean “add this to your SPF record”.
Merging the records
Suppose the domain has these two:
v=spf1 include:spf.protection.outlook.com -all v=spf1 include:servers.mcsv.net ~all
- Copy every
include:,ip4:,ip6:,aandmxterm from all the records into one list, dropping duplicates. - Check each one is a service the domain still uses. Merging is a good moment to remove the ones it doesn't.
- Put
v=spf1at the start and a singleallat the end. Use the stricter of the two if you're confident every sender is listed, otherwise~all. - Edit one of the existing records to the merged version and delete the others.
v=spf1 include:spf.protection.outlook.com include:servers.mcsv.net ~all
Count the lookups after merging: two records that each worked can be over the limit of 10 once combined. If so, see SPF has too many DNS lookups.
Where to edit it
Microsoft 365
Add include:spf.protection.outlook.com. Microsoft's admin centre shows the same value under the domain's DNS records.
Google Workspace
Add include:_spf.google.com.
Mailchimp and SendGrid
Both authenticate a domain with CNAME records that their domain authentication pages give you. SendGrid's automated security points a subdomain of yours at its own servers, and that subdomain is the one SPF checks, so you don't add SendGrid to the root record. Mailchimp's set-up asks for two DKIM CNAMEs and a DMARC record, not an SPF entry. Only add an include if the service's own set-up page asks for one today.
Cloudflare DNS
In the dashboard, open the domain, then DNS, then Records. The SPF record is the TXT record with the name @ whose content starts v=spf1. Edit it there rather than adding a second one.
Questions
Can I keep one SPF record per service?
No. RFC 7208 section 4.5 says that if more than one record starting v=spf1 is found, the result is a permerror. There is no way for a receiver to combine them.
Does a TXT record for something else count?
No. Only records starting v=spf1 count. Verification records for Google, Microsoft and others can sit alongside the SPF record without causing problems.
Hear about it the day it breaks.
Daily checks on every client domain, alerts when something changes, and a monthly report card your clients will understand.