1. Home
  2. Free tools
  3. SPF generator

SPF record generator

Select the services that send email for your domain and this builds a valid SPF TXT record, counting the DNS lookups as it goes. SPF allows ten, and exceeding them makes the whole record fail rather than partially apply — so the counter matters more than the record.

Who sends email for your domain?

IP mechanisms are evaluated inline and cost no DNS lookup — the cheapest way to authorise a server.

Receivers are asked to reject mail from any server not listed. The strongest setting, and the right target once you are sure every legitimate sender is included.

Your SPF record

v=spf1 include:_spf.google.com -all

3 of 10 DNS lookups used

Within the limit, with room to add another vendor later.

Where this goes in DNS

Type
TXT
Name / host
@ (the root domain)
Value
the record above

Publish only one SPF record. Two records beginning v=spf1 is invalid and makes SPF fail entirely — if you already have one, merge these mechanisms into it rather than adding a second.

The lookup limit is what breaks SPF

Almost every broken SPF record we see is broken the same way: it grew past ten DNS lookups. Someone added a fifth email vendor, the count tipped over, and SPF began failing with a permanent error on every message — not just mail from the new vendor.

The counts are not obvious either. include:_spf.google.com costs three lookups on its own, because it nests further includes inside it. Microsoft 365 costs two. So a domain running Google Workspace plus three marketing tools is already at six or seven with nothing unusual configured.

The cheapest fix is IP mechanisms. ip4: and ip6: are evaluated inline and cost nothing, so authorising your own mail server by IP is always free where an include is not.

SPF is one of three records

On its own SPF is weak: it validates the envelope sender rather than the From address a person actually sees, and it breaks whenever a message is forwarded. It only becomes meaningful alongside DKIM, which signs the message and survives forwarding, and DMARC, which ties either result to the visible From domain and says what to do on failure.

Publish SPF first, then DKIM through your provider, then a DMARC record at p=none while you read the reports. Check the result with the SPF checker or the full deliverability audit.

Common questions

How do I create an SPF record?
Select every service that sends email for your domain, add any of your own sending IPs, choose what should happen to unlisted servers, and publish the result as a single TXT record on your root domain. The generator above builds it and counts the DNS lookups as you go.
What should my SPF record end with?
Use -all once you are confident every legitimate sender is listed — it asks receivers to reject mail from anything else. Start with ~all if you are unsure, which accepts unlisted mail but marks it suspicious. Never use +all: it authorises the entire internet to send as your domain.
Why does SPF only allow ten DNS lookups?
The limit exists to stop a single message triggering an unbounded chain of DNS queries. Each include, a, mx, ptr and exists mechanism costs one lookup. The important part is the failure mode: exceeding ten makes the whole record fail with a permanent error rather than ignoring the extras, so a record that worked last month can break by adding one vendor.
How do I fix too many SPF lookups?
Three options. Replace an include with the provider's published IP ranges, since ip4 and ip6 mechanisms cost no lookup at all. Consolidate vendors so you are not authorising four services that do the same job. Or use an SPF flattening service, accepting that it needs to track the provider's IP changes for you.
Can I have two SPF records?
No. Two TXT records beginning v=spf1 is invalid and makes SPF evaluation fail completely, which is worse than one imperfect record. If you already have an SPF record, merge the new mechanisms into it rather than publishing a second.

Records published. Now the list itself.

Authentication stops your mail being forged. It does nothing about the dead addresses that get you throttled in the first place.

  • Bulk verification with real SMTP mailbox checks
  • Hard bounces removed before a send, not discovered after
  • Catch-all, disposable and role detection on every row

One plan, cancel anytime, no contract. The free tools stay free and unmetered either way — they are not a trial.

Ready to clean your email lists?

Start verifying emails today and boost your deliverability.

Get Started

Cancel anytime • No setup required