Email Authentication 6 min read

SPF Record Builder Guide

Use this guide to draft an SPF record, keep the lookup count at 10 or fewer, and stay inside 255 characters. The builder runs in your browser. It does not publish DNS and it does not start Mail Watch.

Overview

SPF tells receiving mail servers which hosts may send mail for your domain. The builder starts with v=spf1 and ends with ~all so unmatched mail is a soft fail while you test. Each include, a, mx, exists, and redirect mechanism spends one of the 10 allowed DNS lookups. Nested includes are not counted on this page. A single TXT string must stay within 255 characters.

What to check before you publish

  • Qualifier: Leave ~all until every legitimate sender is listed. -all rejects everyone else.
  • Lookups: Stay at 10 or fewer, including lookups hidden inside include: hosts.
  • Length: Split or shorten the record if the draft exceeds 255 characters.

SPF draft checklist

ItemDraft defaultWhy it matters
all qualifier~allSoft fail while you confirm senders
DNS lookupsCounted from the mechanisms you typedSPF fails closed after 10 lookups
TXT lengthWarned above 255DNS TXT strings have a 255-character limit

Example draft

Microsoft 365 style draft
v=spf1 include:spf.protection.outlook.com ~all

Recommended Remediation Flow

  1. Draft the record Open the SPF builder. Turn on Include Google Workspace or Include Microsoft 365 if those hosts send mail, add any other includes, and leave ~all selected.
  2. Publish it yourself Copy the draft into your DNS host as a TXT record on the domain. The builder does not publish it.
  3. Check the live record Use Check this domain. It opens the email security checker with the domain filled in.

Troubleshooting Common Issues

The lookup warning appeared with only a few includes

Nested includes are not visible on this page.

  • Ask the email host how many lookups their include uses.
  • Remove unused include mechanisms.
  • Re-check after DNS publishes.

Validation Checklist

Post-fix validation

  • The published TXT matches the draft.
  • The qualifier is ~all or -all on purpose.
  • Mail Watch was not started by this page.

FAQ

Does this start Mail Watch?

No.

  • This is a free draft tool.
  • Mail Watch is a separate paid monitor you start from the dashboard.
  • Publishing DNS is still your step at the DNS host.