Who This Topic Is For
Site owners who want a copy-paste draft before they edit DNS or server configuration.
Draft SPF, DMARC, CSP, and security-header text in the browser, then publish it yourself.
Site owners who want a copy-paste draft before they edit DNS or server configuration.
Use this checklist to make sure the workflow guidance applies cleanly to your current task.
Use this section to set the right outcome before you start the workflow.
Each builder runs in your browser and shows text you can copy. It does not create DNS records, change HTTP headers, or start Mail Watch.
The SPF builder ends with ~all unless you change it. It warns when the mechanisms you typed exceed 10 DNS lookups or the record exceeds 255 characters. Nested includes inside someone else’s SPF are not counted on this page.
The DMARC builder requires a report address and shows the host _dmarc.your-domain. Leave policy at p=none until you have read aggregate reports.
Pick Nginx, Apache, or Cloudflare. HSTS, nosniff, framing, referrer, and permissions follow the toggles. Preload stays off unless you turn it on. Publishing is still a separate step on your server or Cloudflare account.
Follow these steps in order for a reliable and repeatable outcome.
From Tools, open SPF Record Builder, DMARC Record Builder, CSP Builder, or Security Headers Builder.
SPF: turn on Include Google Workspace or Include Microsoft 365 when those hosts send mail, add other includes, and leave ~all.
An empty domain shows a form error when you try to copy. DMARC: enter the domain and a report mailbox.
DKIM alignment and SPF alignment stay Relaxed unless you choose Strict. Percentage stays at 100 unless you change it.
CSP: pick static, WordPress, or Shopify. Headers: pick Nginx, Apache, or Cloudflare, then turn HSTS, includeSubDomains, nosniff, X-Frame-Options, Referrer-Policy, and Permissions-Policy on or off.
Leave HSTS preload off unless the whole domain is ready.
Add the DNS TXT record or server header at your host.
SPF and DMARC use the Check this domain link, which opens the email security checker. CSP and headers use their own checker links.
If you typed a domain, that checker opens with the domain filled in.
These scenarios show how the workflow looks in practice, including the result you should see.
You enter example.com and dmarc@example.com, leave p=none, and copy v=DMARC1; p=none; rua=mailto:dmarc@example.com. You publish that TXT at _dmarc.example.com.
Include Google Workspace is on. The draft contains include:_spf.google.com and ends in ~all. Check this domain opens the email security checker with the domain filled in.
HSTS and includeSubDomains are on. max-age stays 31536000. Preload stays off. The Nginx draft starts with add_header Strict-Transport-Security.
Use this checklist to confirm the workflow was completed correctly.
If something does not match expectation, check these common failure modes first.
The mechanisms you typed already use more than 10 lookups, or a nested include will. Remove unused includes before you publish.
A report address is required. Enter a mailbox such as dmarc@example.com and leave policy at p=none.
The builder does not publish. Add the record at your DNS host or server, wait for DNS, then run the checker again.
Use these links to continue your workflow without losing context.
Open SPF Record Builder to continue this workflow.
Open DMARC Record Builder to continue this workflow.
Open CSP Builder to continue this workflow.
Open Security Headers Builder to continue this workflow.
Open Help: Record Builders to continue this workflow.
Common questions for this topic.
No. You copy the draft and publish it at your DNS host, web server, or Cloudflare account.
Continue to the best next page based on where you are in your workflow.