SPF Record Builder Guide
Use this guide to draft an SPF record, keep the lookup count at 10 or fewer, and stay inside 255 characters. The builder runs in your browser. It does not publish DNS and it does not start Mail Watch.
Overview
SPF tells receiving mail servers which hosts may send mail for your domain. The builder starts with v=spf1 and ends with ~all so unmatched mail is a soft fail while you test. Each include, a, mx, exists, and redirect mechanism spends one of the 10 allowed DNS lookups. Nested includes are not counted on this page. A single TXT string must stay within 255 characters.
What to check before you publish
- Qualifier: Leave ~all until every legitimate sender is listed. -all rejects everyone else.
- Lookups: Stay at 10 or fewer, including lookups hidden inside include: hosts.
- Length: Split or shorten the record if the draft exceeds 255 characters.
SPF draft checklist
| Item | Draft default | Why it matters |
|---|---|---|
| all qualifier | ~all | Soft fail while you confirm senders |
| DNS lookups | Counted from the mechanisms you typed | SPF fails closed after 10 lookups |
| TXT length | Warned above 255 | DNS TXT strings have a 255-character limit |
Example draft
Microsoft 365 style draft
v=spf1 include:spf.protection.outlook.com ~allRecommended Remediation Flow
- Draft the record Open the SPF builder. Turn on Include Google Workspace or Include Microsoft 365 if those hosts send mail, add any other includes, and leave ~all selected.
- Publish it yourself Copy the draft into your DNS host as a TXT record on the domain. The builder does not publish it.
- Check the live record Use Check this domain. It opens the email security checker with the domain filled in.
Troubleshooting Common Issues
The lookup warning appeared with only a few includes
Nested includes are not visible on this page.
- Ask the email host how many lookups their include uses.
- Remove unused include mechanisms.
- Re-check after DNS publishes.
Validation Checklist
Post-fix validation
- The published TXT matches the draft.
- The qualifier is ~all or -all on purpose.
- Mail Watch was not started by this page.
FAQ
Does this start Mail Watch?
No.
- This is a free draft tool.
- Mail Watch is a separate paid monitor you start from the dashboard.
- Publishing DNS is still your step at the DNS host.