Skip to content
SPF

No SPF record: how to add one

Your domain has no SPF record, so receivers can't tell which servers may send its email. How to build one for Microsoft 365, Google and others.

By the Domain Health Hub team · Updated

In short
  • SPF is one TXT record at the domain root listing the servers allowed to send its email.
  • Without it, genuine email is more likely to land in spam and DMARC has only DKIM to go on.
  • List every service that sends as the domain, end with ~all, and move to -all once you're sure.

What it means

We looked up the TXT records at the root of the domain and none of them starts v=spf1. That record is SPF (Sender Policy Framework, RFC 7208): the list of servers allowed to send email that uses the domain in its envelope sender, the hidden return address bounces go to.

Why it matters

Without SPF, a receiving server has no way to tell your mail servers from anyone else's. Gmail, Yahoo and Microsoft all expect senders to publish SPF, and Gmail and Yahoo require it from anyone sending in bulk. SPF is also one of the two ways an email can pass DMARC. With no SPF record, every message relies on DKIM alone, and forwarding or a missing signature leaves nothing to fall back on.

Building the record

Make a list of everything that sends email as the domain before you write anything: the mailbox provider, newsletter tool, helpdesk, CRM, invoicing system, website contact form and any office printer or scanner that emails. Then add one entry for each.

example.com TXT
v=spf1 include:spf.protection.outlook.com include:_spf.google.com ~all
v=spf1
Must come first. Exactly one record per domain may start with it.
include:
Adds a service's own list. Use the value from the provider's set-up page.
ip4: ip6:
Allows one address or a range, for a server you run yourself.
~all
Anything not listed softfails. Change to -all (fail) once you're sure.

Keep an eye on the count: receivers stop after 10 DNS lookups, and each include uses at least one. If you have a long list of services, read SPF has too many DNS lookups before you publish.

Provider by provider

Microsoft 365

Add include:spf.protection.outlook.com. Microsoft's admin centre shows the same value under the domain's DNS records.

Google Workspace

Add include:_spf.google.com.

Mailchimp and SendGrid

Both authenticate a domain with CNAME records that their domain authentication pages give you. SendGrid's automated security points a subdomain of yours at its own servers, and that subdomain is the one SPF checks, so you don't add SendGrid to the root record. Mailchimp's set-up asks for two DKIM CNAMEs and a DMARC record, not an SPF entry. Only add an include if the service's own set-up page asks for one today.

Cloudflare DNS

In the dashboard, open the domain, then DNS, then Records. The SPF record is the TXT record with the name @ whose content starts v=spf1. Edit it there rather than adding a second one.

Domains that never send email

Parked domains and website-only domains still need SPF, because otherwise they're easy to impersonate. Publish a record that allows nobody:

parked-example.com TXT
v=spf1 -all

Pair it with a DMARC record at p=reject, and see null MX if the domain shouldn't receive email either.

Questions

Should I use ~all or -all?

Start with ~all (softfail) while you confirm every sender is listed, then change to -all. With DMARC at quarantine or reject, receivers act on the DMARC result, so the difference matters less than people think.

Where does the record go?

At the domain itself, the name often written as @ in DNS control panels. Not at www and not at a subdomain, unless that subdomain sends email of its own.

Hear about it the day it breaks.

Daily checks on every client domain, alerts when something changes, and a monthly report card your clients will understand.

Start 28-day free trial