SPF — Sender Policy Framework
How SPF protects your domain by authorizing which servers can send email on your behalf.
What is SPF?
SPF (Sender Policy Framework) is a DNS-based email authentication protocol defined in RFC 7208. It allows domain owners to specify which mail servers are authorized to send email on behalf of their domain. When an email is received, the recipient's mail server checks the SPF record in DNS to verify that the sending server is permitted to send mail for that domain.
How SPF Works
When an email is sent, the receiving mail server extracts the domain from the "envelope from" (Return-Path) address and queries DNS for a TXT record at that domain beginning with "v=spf1". The record lists authorized IP addresses and mechanisms. The server evaluates the sending IP against these rules and returns a result: Pass, Fail, SoftFail, Neutral, None, TempError, or PermError.
SPF Record Syntax
An SPF record is a DNS TXT record. Example:
v=spf1 include:_spf.google.com include:sendgrid.net ip4:203.0.113.5 ~allCommon mechanisms:
• ip4 / ip6 — authorize specific IP addresses
• include — reference another domain's SPF record
• a — authorize the domain's A record IP
• mx — authorize the domain's MX record IPs
• all — catch-all (use -all for hard fail, ~all for soft fail)
Modifiers: redirect= and exp= can alter SPF evaluation.
SPF Limitations
SPF only validates the envelope sender (Return-Path), not the visible "From" header that users see. This means SPF alone does not prevent display-name spoofing. SPF also breaks when email is forwarded, because the forwarding server's IP is not in the original domain's SPF record. SPF has a 10 DNS lookup limit — exceeding it causes a PermError. Use DMARC alongside SPF to get meaningful protection.
Common SPF Issues
• Too many DNS lookups (>10): flatten your SPF record or use a service like MailGeeks.com.
• Missing sending sources: if a third-party ESP sends on your behalf, add their include: mechanism.
• Hard fail on legitimate traffic: use ~all during rollout, then tighten to -all once validated.
• Multiple SPF records: only one TXT record starting with "v=spf1" is allowed per domain.
SPF Best Practices
1. Always pair SPF with DKIM and DMARC for full email authentication.
2. Start with ~all (softfail) and monitor DMARC reports before switching to -all.
3. Keep your SPF record up to date as you add or remove ESPs.
4. Avoid +all — it authorizes every server in the world to send as your domain.
5. Test your SPF record regularly using tools like EmailTest.ai.
Related