Documentation

Record Builders

Draft SPF, DMARC, CSP, and security-header text in the browser, then publish it yourself.

Who This Topic Is For

Site owners who want a copy-paste draft before they edit DNS or server configuration.

Prerequisites

Before You Start

Use this checklist to make sure the workflow guidance applies cleanly to your current task.

  • You can edit DNS or server headers for the domain, or you can hand the draft to someone who can.
  • You know which email hosts send mail for the domain before you write SPF or DMARC.
Expectations

What To Expect

Use this section to set the right outcome before you start the workflow.

A draft, not a published record

Each builder runs in your browser and shows text you can copy. It does not create DNS records, change HTTP headers, or start Mail Watch.

SPF starts at ~all

The SPF builder ends with ~all unless you change it. It warns when the mechanisms you typed exceed 10 DNS lookups or the record exceeds 255 characters. Nested includes inside someone else’s SPF are not counted on this page.

DMARC starts at p=none

The DMARC builder requires a report address and shows the host _dmarc.your-domain. Leave policy at p=none until you have read aggregate reports.

Headers are a draft for one server

Pick Nginx, Apache, or Cloudflare. HSTS, nosniff, framing, referrer, and permissions follow the toggles. Preload stays off unless you turn it on. Publishing is still a separate step on your server or Cloudflare account.

Playbook

Step-By-Step Guidance

Follow these steps in order for a reliable and repeatable outcome.

  1. Open the builder you need.

    From Tools, open SPF Record Builder, DMARC Record Builder, CSP Builder, or Security Headers Builder.

  2. Fill the form and copy the draft.

    SPF: turn on Include Google Workspace or Include Microsoft 365 when those hosts send mail, add other includes, and leave ~all.

    An empty domain shows a form error when you try to copy. DMARC: enter the domain and a report mailbox.

    DKIM alignment and SPF alignment stay Relaxed unless you choose Strict. Percentage stays at 100 unless you change it.

    CSP: pick static, WordPress, or Shopify. Headers: pick Nginx, Apache, or Cloudflare, then turn HSTS, includeSubDomains, nosniff, X-Frame-Options, Referrer-Policy, and Permissions-Policy on or off.

    Leave HSTS preload off unless the whole domain is ready.

  3. Publish it yourself, then check the live result.

    Add the DNS TXT record or server header at your host.

    SPF and DMARC use the Check this domain link, which opens the email security checker. CSP and headers use their own checker links.

    If you typed a domain, that checker opens with the domain filled in.

Examples

Worked Examples

These scenarios show how the workflow looks in practice, including the result you should see.

First DMARC record

You enter example.com and dmarc@example.com, leave p=none, and copy v=DMARC1; p=none; rua=mailto:dmarc@example.com. You publish that TXT at _dmarc.example.com.

The DNS checker can then see the record. Mail Watch is still off until you subscribe to it separately.

Google Workspace SPF include

Include Google Workspace is on. The draft contains include:_spf.google.com and ends in ~all. Check this domain opens the email security checker with the domain filled in.

The checker reads the live DNS record, not the draft. Publish the TXT first, then run the check.

Nginx HSTS draft

HSTS and includeSubDomains are on. max-age stays 31536000. Preload stays off. The Nginx draft starts with add_header Strict-Transport-Security.

Check live security headers still shows the old header until that line is published on the server.
Validation

Validation Checklist

Use this checklist to confirm the workflow was completed correctly.

  • The copied text matches what you intended to publish.
  • SPF still ends in ~all unless you chose another qualifier on purpose.
  • DMARC policy is p=none and the host is _dmarc.your-domain.
  • HSTS preload is off unless you turned it on.
  • The live checker was run after you published, and Mail Watch was not started by the builder.
Troubleshooting

Common Problems And Fixes

If something does not match expectation, check these common failure modes first.

SPF warning about 10 lookups

The mechanisms you typed already use more than 10 lookups, or a nested include will. Remove unused includes before you publish.

Common failure mode

DMARC form will not copy

A report address is required. Enter a mailbox such as dmarc@example.com and leave policy at p=none.

Common failure mode

The live checker does not show the draft

The builder does not publish. Add the record at your DNS host or server, wait for DNS, then run the checker again.

Common failure mode
FAQ

Record Builders FAQs

Common questions for this topic.

No. You copy the draft and publish it at your DNS host, web server, or Cloudflare account.

Next Recommended Action

Continue to the best next page based on where you are in your workflow.