Skip to content
SPF

SPF record syntax error: how to fix it

An SPF record with a typo or an unknown term fails for every email. The common mistakes, how to spot them and how to correct the record.

By the Domain Health Hub team · Updated

In short
  • One unknown or badly formed term makes the whole record a permanent error, so SPF fails for all mail.
  • The usual causes are typos, stray spaces, smart quotes from a word processor and pasted placeholders.
  • Fix the term the checker names, then look at the record again as a whole.

What it means

The domain has one SPF record, but it contains something the standard doesn't allow. Under RFC 7208, a receiver that meets a term it can't parse stops and returns a permanent error. That fails SPF for every message, exactly as if the record were wrong for every sender, and DMARC can only pass on DKIM.

Common mistakes

includes:
A misspelt mechanism. Only include, a, mx, ip4, ip6, ptr, exists and all exist.
include: x.com
A space after the colon splits it into two broken terms.
ip4:1.2.3
An incomplete address or a range written with a dash instead of a /prefix.
“v=spf1 ...”
Curly quotes pasted from a document end up inside the record.
v=spf1 ... -all ip4:
Terms after all are never reached; tidy them into place.
<your-ip>
A placeholder from a set-up guide that was never replaced.

Two more to watch for: a record split across two TXT records instead of two strings in one record (a long record can be split into strings of up to 255 characters, but they must be in the same record), and a record published as the old SPF record type instead of TXT. Only TXT counts today.

Fixing it

  1. Open the domain's DNS and find the TXT record starting v=spf1.
  2. Correct the term the checker named. If you aren't sure what a term was meant to be, compare it with the sending service's current set-up page.
  3. Read the rest of the record from left to right: one v=spf1 at the start, single spaces between terms, and one all at the end.
  4. Save it and check the domain again. Most DNS changes show within a few minutes.

Cloudflare DNS

Paste the record as plain text. If it was copied from a document, check the quotation marks haven't been turned into curly quotes, which Cloudflare stores as part of the value.

Questions

Is spf2.0 a typo?

Not exactly: spf2.0/pra is Sender ID, an old Microsoft standard that was retired. It isn't SPF and receivers ignore it. Delete it and make sure a v=spf1 record exists.

Is SPF case sensitive?

No. Mechanisms and domain names are case insensitive, but stick to lower case so the record is easy to read.

Hear about it the day it breaks.

Daily checks on every client domain, alerts when something changes, and a monthly report card your clients will understand.

Start 28-day free trial