Generator / Guides / Syntax
SPF syntax, every part
An SPF record is one line of text. It always starts with v=spf1, lists who may send, and ends with what to do about everyone else. Here is every piece, from the standard itself.
Anatomy of a record
v=spf1 include:_spf.google.com ip4:203.0.113.5 ~all
v=spf1: the version. Must come first, exactly like this.- Then mechanisms, read left to right. The first one that matches the sending server decides the result.
- Each mechanism can carry a qualifier in front (
+ - ~ ?). ~allor-allat the end catches everyone not listed.
Source: RFC 7208, section 4.6, checked Oct 2026
The eight mechanisms
allMatches everything. Always last; its qualifier says what happens to senders not listed.Costs a lookup: NoExample: -allinclude:Checks another domain's SPF record; a pass there is a pass here. How services like Google are added.Costs a lookup: YesExample: include:_spf.google.comaAllows the IP addresses of a domain's A/AAAA records (your own domain if no name is given).Costs a lookup: YesExample: amxAllows the servers listed in a domain's MX records.Costs a lookup: YesExample: mxip4:Allows one IPv4 address or a range.Costs a lookup: NoExample: ip4:203.0.113.0/24ip6:Allows one IPv6 address or a range.Costs a lookup: NoExample: ip6:2001:db8::/32exists:Matches if a DNS name exists. Used by a few large senders for per-sender rules.Costs a lookup: YesExample: exists:%{i}.spf.example.comptrReverse-DNS check. Slow and unreliable; the standard says not to use it.Costs a lookup: YesExample: (avoid)Source: RFC 7208, section 5, checked Oct 2026
The four qualifiers
The default when no qualifier is written. "+all" lets anyone send as you: never use it.
Not allowed. Receivers may reject the message.
Probably not allowed. Receivers accept it but treat it as suspicious.
No opinion. Rarely useful.
Source: RFC 7208, section 4.6.2, checked Oct 2026
The two modifiers
redirect=example.com: use another domain's record instead of this one, when nothing here matched. Costs one lookup. Useful when many domains share one policy.exp=explain.example.com: points at a text record that explains a failure. Rarely used.
Source: RFC 7208, section 6, checked Oct 2026
Three rules that catch people out
- One SPF record per domain. Two records starting with
v=spf1is a permerror; receivers ignore both. Merge them. (RFC 7208, section 3.2) - 255 characters per text string. DNS stores TXT records in strings of up to 255 characters. A longer record is split into several strings that are joined back together without spaces; most DNS editors do this for you. (section 3.3)
- It goes on the exact name that sends. A record on yourdomain.com doesn't cover news.yourdomain.com; each name needs its own.
Source: RFC 7208, section 3, checked Oct 2026
