100% Client-Side EngineZero data storage • No email signup required • 2026 Google & Yahoo Bulk Sender Compliant
RFC 7208 Standard Compliant Engine

SPF Record Generator & Smart Merger

Combine multiple email service providers into a single, valid SPF record. Calculate real-time DNS lookups to guarantee compliance with the RFC 7208 10-lookup ceiling.

Real-time RFC 7208 10-lookup validation active

SPF Record Generator

Select your sending mail services to assemble an RFC 7208 compliant SPF TXT record.

DNS Lookups Consumed
Generated SPF RecordTXT Record
v=spf1 mx include:_spf.google.com ~all
RFC 7208 DNS Lookups2 / 10 Lookups

Optimal: Safe within RFC 7208 10-lookup limits.

DNS Configuration Table

Type
Host / Name
Value / Content
TXT
@ (Root)
v=spf1 mx include:_spf.google.com ~all
Provider Host Syntax:

Host: @ • Cloudflare will automatically attach your root domain.

The 10-DNS-Lookup Trap (RFC 7208 §4.6.4)

To protect mail servers from Distributed Denial of Service (DDoS) loops, RFC 7208 mandates that evaluating an SPF record must not trigger more than 10 DNS queries.

Providers like Google Workspace consume 1 lookup, but others (like HubSpot, Zendesk, or Salesforce) can consume 2 to 4 lookups internally. If your combined mechanisms exceed 10 lookups, Gmail and Yahoo return a PermError and drop your emails.

The Single Record Invariant (RFC 7208 §3.2)

A domain name MUST NOT have more than one SPF TXT record published in DNS. If two records exist (e.g., one for Google and another for Mailchimp), mail receivers abort validation immediately.

You must merge all sender authorizations into a single string starting with v=spf1 and ending with your all qualifier. Our smart merger handles this automatically.

Verified Provider Include Directives (2026)

Standard SPF include strings verified against provider documentation and live DNS records.

View All 12 Setup Guides
ProviderSPF Include MechanismDNS LookupsNotes
Google Workspaceinclude:_spf.google.com1Standard for Gmail and Google Workspace accounts
Microsoft 365 (Office 365)include:spf.protection.outlook.com1Includes Outlook, Exchange Online, and Defender
HubSpot Emailinclude:[portal-id].spf01.hubspotemail.net1Uses dynamic portal ID routing per HubSpot standard
SendGrid (Twilio)include:sendgrid.net1Transactional sending infrastructure
Amazon SESinclude:amazonses.com1AWS Simple Email Service global authentication
Mailchimpinclude:servers.mcsv.net1Marketing campaign servers

How to Publish Your Generated SPF Record

1

Open DNS Manager

Log into your domain registrar or DNS hosting provider (Cloudflare, GoDaddy, Namecheap, AWS Route 53, etc.).

2

Create or Replace TXT Record

Set Record Type to TXT, Host/Name to @ (or leave blank depending on your registrar), and paste the generated string.

3

Verify Live Propagation

Use our DNS Inspector to ensure the new record is live across global Anycast nameservers.

Frequently Asked Questions About SPF

Everything you need to know about Sender Policy Framework syntax, limits, and best practices.

What is the SPF 10-lookup limit in RFC 7208?

RFC 7208 Section 4.6.4 specifies that the evaluation of an SPF record must not exceed 10 DNS lookups (from include, a, mx, ptr, and exists mechanisms). If a receiver requires more than 10 lookups to evaluate your SPF record, it aborts evaluation with a permanent error (PermError), causing genuine business emails to fail authentication and land in spam folders.

Why can I not have two separate SPF TXT records for one domain?

RFC 7208 Section 3.2 explicitly dictates that a domain MUST NOT publish more than one SPF record. If receiving mail servers (such as Gmail, Yahoo, or Outlook) discover more than one SPF TXT record beginning with "v=spf1", they immediately fail validation with a PermError without even evaluating the contents.

What is the difference between ~all (SoftFail) and -all (Fail)?

~all (SoftFail) indicates that unlisted sending servers are not authorized, but the receiver should still accept the message while marking it suspicious. -all (Fail/HardFail) instructs receivers to reject unlisted senders outright. In modern DMARC setups, ~all is standard practice because DMARC policies (p=quarantine or p=reject) dictate final disposition.

Does an "ip4" or "ip6" directive count toward the 10-lookup limit?

No. IP mechanisms ("ip4:192.0.2.0/24" and "ip6:2001:db8::/32") do not require DNS queries; their values are embedded directly in the record text. As a result, they consume 0 lookups against the RFC 7208 10-lookup budget.

Enterprise Email Infrastructure

Email Authentication Configured. What’s Next for Inbox Protection?

DNS authentication is the prerequisite. Next-level email deliverability requires robust nameservers, clean business mailboxes, and automated RUA report ingestion.

Disclosure: Some links on this page are affiliate links. If you make a purchase through them, we may earn a commission at no additional cost to you. We only recommend tools that meet strict deliverability and security standards.
Recommended by DMARCPro
Recommended Business InfrastructureSponsored

Google Workspace

Standardize @yourcompany.com on Google Infrastructure

Industry standard business email with native SPF and DKIM signing. Maintain clean sender reputation with dedicated enterprise IP ranges and built-in abuse prevention.

99.9% guaranteed enterprise SLA
Native 2-step verification & advanced phishing protection
1-click DNS authentication with major registrars
Official Partner 10% Referral Discount Eligible
Get Google Workspace (10% Off)
Monitoring ArchitectureDocumentation

DMARC RUA Report Pipeline

Aggregate XML Telemetry & Spoofing Alerts

Publishing p=reject without monitoring aggregate XML reports (rua=) risks dropping legitimate transactional email. Set up automated parser dashboards to audit every sending IP.

Automated daily aggregate XML parsing
Sender IP geolocation & PTR reverse DNS audit
Instant SPF/DKIM alignment failure alerts
DNS Propagation & SecurityDocumentation

Enterprise DNS Infrastructure

Sub-second Anycast DNS with DNSSEC Support

Slow or unauthenticated DNS servers cause email verification timeouts (DNS TempError). Pair your SPF and DMARC with Anycast nameservers that support automated DNSSEC.

Global Anycast edge network with <10ms resolution
Hardware-backed DNSSEC cryptographic validation
Instant TTL propagation for emergency policy changes