What Is SPF Email and How Does SPF Email Work?

What Is SPF Email? How SPF Records Work, With Examples

What is SPF email?

SPF (Sender Policy Framework) is an email authentication standard that lets a domain owner publish, in DNS, the list of mail servers allowed to send email for that domain. When a message arrives, the receiving server checks whether the sending server's IP address is on that list. If it is, SPF passes; if it is not, the message can be flagged, sent to spam or rejected.

"SPF email" usually means an email sent from a domain that has a valid SPF record. SPF is one of three DNS records that work together to prove a sender is genuine: SPF, DKIM and DMARC. Missing or broken SPF is one of the top reasons WordPress emails go to spam, and one of the first things to fix if you want to prevent email spoofing of your domain.

Key takeaways

  • An SPF record is a single DNS TXT record that starts with v=spf1 and ends with an all mechanism such as ~all or -all.
  • SPF checks the envelope sender (Return-Path), not the From address people see. DMARC is what ties SPF to the visible From domain.
  • A domain can have only one SPF record, and evaluating it may trigger no more than 10 DNS lookups.
  • Since February 2024, Gmail and Yahoo require SPF or DKIM from every sender, and SPF, DKIM and DMARC from bulk senders.
  • If you send with Mailpro, add include:spf.mailpro.com to your SPF record.

How does SPF email work?

SPF works by comparing the IP address of the server delivering a message with the list of authorized senders published in the sender domain's DNS. Step by step:

  1. The domain owner publishes an SPF record. It is a TXT record on the domain, for example v=spf1 include:spf.mailpro.com ~all.
  2. An email is sent. The sending server connects to the recipient's server and announces the envelope sender in the SMTP MAIL FROM command (this address later appears as the Return-Path header).
  3. The receiver looks up SPF. The receiving server takes the domain of the envelope sender and queries DNS for its SPF record.
  4. The IP is evaluated. The receiver reads the record from left to right and checks the connecting IP against each mechanism (ip4, ip6, include, a, mx...). The first mechanism that matches decides the result.
  5. A result is produced. The outcome is pass, fail, softfail, neutral, none, temperror or permerror.
  6. The receiver applies its policy. A pass builds trust. A fail or softfail is combined with DKIM, DMARC and reputation signals to decide between inbox, spam folder or rejection.

You can see the result in the headers of any email you receive, for example: Authentication-Results: mx.google.com; spf=pass [email protected] or Received-SPF: pass.

What does an SPF record look like?

An SPF record is one line of text published as a DNS TXT record on your domain (host @). It always starts with the version tag v=spf1, lists the authorized senders, and ends with a rule for everyone else. Some real-world examples:

Scenario SPF record
Only Mailpro sends for the domain v=spf1 include:spf.mailpro.com ~all
Mailpro + Google Workspace v=spf1 include:spf.mailpro.com include:_spf.google.com ~all
Mailpro + Microsoft 365, strict policy v=spf1 include:spf.mailpro.com include:spf.protection.outlook.com -all
Your own mail server by IP v=spf1 ip4:203.0.113.10 ip6:2001:db8::10 -all
Domain that never sends email v=spf1 -all

Read the second example from left to right: "this is an SPF version 1 record; servers authorized by Mailpro and by Google may send for this domain; treat everything else as a soft fail." Note the include names are exact: Mailpro's is spf.mailpro.com, Google's is _spf.google.com. A typo in an include hostname makes the whole record fail with a permerror.

SPF mechanisms and qualifiers explained

Mechanisms say which servers match; qualifiers say what happens when they match. If a mechanism has no qualifier, + (pass) is assumed.

Mechanism What it matches DNS lookup?
ip4: An IPv4 address or range, e.g. ip4:203.0.113.0/24 No
ip6: An IPv6 address or range, e.g. ip6:2001:db8::/32 No
include: Every sender authorized by another domain's SPF record (used for email providers) Yes (plus any lookups inside it)
a The IP addresses in the domain's A/AAAA records Yes
mx The servers listed in the domain's MX records Yes
exists: Matches if a given domain name resolves (advanced, used with macros) Yes
ptr Reverse DNS match. Deprecated: do not use Yes
all Everything not matched before; always last No
redirect= (modifier) Uses another domain's SPF record instead of this one Yes
Qualifier Result Typical use
+ (default) Pass Authorized senders. Never use +all: it authorizes the whole internet.
- Fail (hard fail) -all: reject anything not listed. Use once you are sure every sender is in the record.
~ Softfail ~all: accept but mark as suspicious. The safe starting point, and common when DMARC enforces the policy.
? Neutral ?all: no opinion. Only for testing.

~all or -all?

Start with ~all while you inventory your senders, then move to -all when you are confident nothing legitimate is missing. Once DMARC is enforced (p=quarantine or p=reject), many senders keep ~all and let DMARC make the final decision, because a hard SPF fail can cause some receivers to reject a message before DKIM is even checked.

The SPF 10 DNS lookup limit

SPF evaluation may trigger at most 10 DNS lookups. Each include, a, mx, exists, ptr and redirect counts, including the ones nested inside the records you include; ip4, ip6 and all do not. Go over 10 and the result is a permerror, which receivers treat as an SPF failure. The rule comes from RFC 7208, the 2014 standard that defines SPF, and exists to stop SPF checks being abused for denial-of-service attacks.

Lookups add up faster than records suggest: one include for a large provider can use three or four lookups on its own. Mailpro's include costs one lookup, because spf.mailpro.com lists IP ranges directly. To stay under the limit:

  • Remove includes for services you no longer use.
  • Replace a and mx with ip4/ip6 when your server IPs are stable.
  • Move secondary senders (helpdesk, CRM, invoicing) to a subdomain with its own SPF record.
  • Be careful with SPF "flattening" (replacing includes with IP lists): it breaks silently when a provider changes its IPs.

RFC 7208 also limits "void lookups" (lookups that return nothing) to two, and each DNS TXT string to 255 characters; longer records must be split into several quoted strings within the same record.

Sending with Mailpro? Your SPF record needs one include, and the dashboard shows the exact value to copy. Then add DKIM and DMARC from the same place: see email authentication.

SPF vs DKIM vs DMARC: what is the difference?

SPF authorizes servers, DKIM signs messages, and DMARC tells receivers what to do when checks fail. They answer different questions, and you need all three.

SPF DKIM DMARC
Question it answers Is this server allowed to send for the domain? Was this message signed by the domain, and is it unchanged? Do SPF or DKIM pass for the From domain, and what if they don't?
What it checks Sending IP vs envelope sender (Return-Path) domain Cryptographic signature in the message header Alignment of SPF/DKIM with the visible From domain
DNS record TXT on the domain: v=spf1 ... TXT at selector._domainkey: public key TXT at _dmarc: v=DMARC1; p=...
Survives forwarding? Usually no (the forwarder's IP is not listed) Usually yes, if the message is not modified Passes if DKIM still passes
Main limitation Does not protect the visible From address on its own Does not say what to do on failure Needs SPF or DKIM to be in place first

For the full picture, read our guide to SPF, DKIM and DMARC, or the FAQs What is a DKIM record? and What is DMARC? In Mailpro, DKIM configuration and the DMARC record are set up alongside SPF.

Is SPF required by Gmail and Yahoo?

Yes. Since February 2024, Gmail and Yahoo require every sender to authenticate with SPF or DKIM. Bulk senders, meaning those sending around 5,000 or more messages a day to personal Gmail accounts, must pass both SPF and DKIM, publish a DMARC record (p=none at minimum) with the From domain aligned to SPF or DKIM, offer one-click unsubscribe and keep spam complaints below 0.30%. Microsoft applies similar rules to Outlook.com, Hotmail and Live addresses since 2025. Our Gmail and Yahoo sender requirements checklist covers every point.

How to set up SPF for your domain

  1. List every service that sends email as your domain: your mailbox provider (Google Workspace, Microsoft 365), your email marketing platform, your website or WordPress server, CRM, helpdesk, invoicing tool.
  2. Check for an existing record. Look for a TXT record on your root domain that starts with v=spf1. If one exists, edit it; never add a second one.
  3. Build one record with one include or ip4/ip6 per sender, ending in ~all.
  4. Publish it at your DNS host as a TXT record on host @. Propagation usually takes minutes, sometimes up to 24 hours.
  5. Test it with an SPF checker and by sending a message to a Gmail address and reading the headers (Show original: "SPF: PASS").
  6. Tighten it to -all when everything passes, and add DKIM and DMARC.

Mailpro users can follow the step-by-step guide to configure SPF with Mailpro; the exact value is also shown in your account's authentication section and on the SPF configuration page.

How to check and troubleshoot SPF

To check a domain's SPF record, run dig TXT example.com +short (Mac/Linux) or nslookup -type=txt example.com (Windows), or use any online SPF checker. Then look at the headers of a real message to see the result receivers get. The most common problems:

Symptom Likely cause Fix
spf=permerror Two SPF records, a syntax error, a misspelled include, or more than 10 lookups Merge into one record, correct the hostname, remove unused includes
spf=fail or softfail for your own mail A sending service is missing from the record Add its include or IP range
spf=none No SPF record found on the envelope sender domain (subdomains do not inherit the parent's SPF) Publish a record on the exact domain used in the Return-Path
spf=temperror Temporary DNS timeout Usually resolves itself; check DNS host health if it repeats
Fails only for some recipients Forwarding: the forwarding server's IP is not in your record Rely on DKIM for DMARC alignment; ARC helps forwarders preserve results
Fails over IPv6 only Your server sends over IPv6 but the record lists only IPv4 Add ip6: ranges; see why SPF fails with IPv6

Frequently asked questions

What does SPF stand for in email?

SPF stands for Sender Policy Framework. It was first proposed in the early 2000s and is defined today by RFC 7208, published in 2014.

Can I have two SPF records?

No. A domain must have exactly one SPF record. Two records produce a permerror and SPF fails for every message. Merge all senders into one record with several include mechanisms.

Does SPF protect the From address my recipients see?

Not on its own. SPF checks the envelope sender (Return-Path). A spammer can pass SPF with their own Return-Path domain while showing your domain in From. DMARC closes that gap by requiring alignment between the two.

Does SPF alone keep my emails out of spam?

No. SPF is required, but inbox placement also depends on DKIM, DMARC, sender reputation, list quality and engagement. Our email deliverability hub explains the other factors.

Do subdomains need their own SPF record?

Yes. SPF records are not inherited. If you send from news.example.com, that subdomain needs its own record.

How often should I update my SPF record?

Whenever you add or remove a service that sends email as your domain, and as part of a yearly review. Stale includes waste lookups and authorize services you no longer control.

Keep your accounts safe too: read the cyber hygiene best practices everyone should follow and how to spot phishing.

Mailpro and SPF

SPF, DKIM and DMARC, set up in minutes

Mailpro gives you ready-to-paste DNS records and checks them for you, so your domain passes the authentication checks Gmail and Yahoo require. Swiss-hosted, GDPR-ready, priced by emails sent.

Start free with Mailpro See email authentication

Previous Article

   

Next Article

You might also be interested in:

As we embrace the digital era, email marketing has become an essential tool for businesses to connect with their audiences. But just as we strive for sustainability in physical resources, we must also address the environmental im...
Email marketing remains a powerful tool for connecting with audiences, but it’s increasingly being challenged by a phenomenon known as email fatigue. This state of mental exhaustion occurs when subscribers feel overwhelmed by the...
In email marketing, deliverability is key. One of the simplest yet often overlooked strategies for improving email deliverabilityis encouraging subscribers to add your email address to their whitelist. Whitelisting ensures your ...
Importance of Password Reset Emails Password reset emails are a critical component of user account security and user experience. These transactional emails as a lifeline for users who have forgotten their passwords, providing t...
Email marketing is an art and a science. While content, design, and strategy play crucial roles, understanding the neuroscience behind how the human brain reacts to emails can give marketers a significant edge. By tapping into th...