Skip to main content

Generator / Guides / Syntax

SPF syntax, every part

An SPF record is one line of text. It always starts with v=spf1, lists who may send, and ends with what to do about everyone else. Here is every piece, from the standard itself.

Anatomy of a record

v=spf1 include:_spf.google.com ip4:203.0.113.5 ~all

  • v=spf1: the version. Must come first, exactly like this.
  • Then mechanisms, read left to right. The first one that matches the sending server decides the result.
  • Each mechanism can carry a qualifier in front (+ - ~ ?).
  • ~all or -all at the end catches everyone not listed.

Source: RFC 7208, section 4.6, checked Oct 2026

The eight mechanisms

MechanismWhat it doesCosts a lookupExample
allMatches everything. Always last; its qualifier says what happens to senders not listed.Costs a lookup: NoExample: -all
include:Checks another domain's SPF record; a pass there is a pass here. How services like Google are added.Costs a lookup: YesExample: include:_spf.google.com
aAllows the IP addresses of a domain's A/AAAA records (your own domain if no name is given).Costs a lookup: YesExample: a
mxAllows the servers listed in a domain's MX records.Costs a lookup: YesExample: mx
ip4:Allows one IPv4 address or a range.Costs a lookup: NoExample: ip4:203.0.113.0/24
ip6:Allows one IPv6 address or a range.Costs a lookup: NoExample: ip6:2001:db8::/32
exists:Matches if a DNS name exists. Used by a few large senders for per-sender rules.Costs a lookup: YesExample: exists:%{i}.spf.example.com
ptrReverse-DNS check. Slow and unreliable; the standard says not to use it.Costs a lookup: YesExample: (avoid)

Source: RFC 7208, section 5, checked Oct 2026

The four qualifiers

+Pass

The default when no qualifier is written. "+all" lets anyone send as you: never use it.

-Fail

Not allowed. Receivers may reject the message.

~Softfail

Probably not allowed. Receivers accept it but treat it as suspicious.

?Neutral

No opinion. Rarely useful.

Source: RFC 7208, section 4.6.2, checked Oct 2026

The two modifiers

  • redirect=example.com: use another domain's record instead of this one, when nothing here matched. Costs one lookup. Useful when many domains share one policy.
  • exp=explain.example.com: points at a text record that explains a failure. Rarely used.

Source: RFC 7208, section 6, checked Oct 2026

Three rules that catch people out

  1. One SPF record per domain. Two records starting with v=spf1 is a permerror; receivers ignore both. Merge them. (RFC 7208, section 3.2)
  2. 255 characters per text string. DNS stores TXT records in strings of up to 255 characters. A longer record is split into several strings that are joined back together without spaces; most DNS editors do this for you. (section 3.3)
  3. It goes on the exact name that sends. A record on yourdomain.com doesn't cover news.yourdomain.com; each name needs its own.

Source: RFC 7208, section 3, checked Oct 2026

Build a valid record

Ari from Consult With Ari

Website designed and built with love by Consult With Ari

You Have a Business to Grow. Let Me Handle the Internet.

Websites, SEO, social media, ads and IT support for small businesses. Based in Jerusalem and New York City, working with clients all over the world.

Rated 5 stars on Wix and GoogleWix Legend Partner | Base44 Specialist Partner
Book a free callConsultWithAri.com