Email Marketing

SPF (Sender Policy Framework)

Also called Sender Policy Framework, SPF record

A DNS record listing the servers allowed to send email for your domain, so receiving servers can spot mail from anywhere else.

Quick facts: SPF (Sender Policy Framework)

Category
Email Marketing
Also called
Sender Policy Framework, SPF record
Level
Intermediate
Affects
Deliverability, spoofing protection, DMARC compliance
Where to see it
Your DNS host or domain registrar, DNS lookup tools, DMARC reports, Google Postmaster Tools
In this article4
  1. How SPF works
  2. Why it matters
  3. Common mistakes
  4. How to act on it

SPF (Sender Policy Framework) is an email authentication standard that lets a domain owner publish a list of the servers allowed to send email on its behalf. Receiving mail servers check that list, and mail from a server that is not on it is more likely to be rejected or sent to spam.

How SPF works

SPF lives in a single TXT record in your domain’s DNS. A business using Microsoft 365 for staff email and a separate platform for newsletters might publish something like this, where the second include stands in for the value your email platform gives you:

v=spf1 include:spf.protection.outlook.com include:mail.example-platform.com ~all

Reading left to right: “v=spf1” marks the record as SPF; each “include” adds a provider’s servers; “~all” tells receivers to treat anything else with suspicion, which is called a soft fail. “-all” is a hard fail, asking receivers to reject unlisted senders outright.

The check is made against the domain in the hidden return path, also called the envelope sender, not the “From” address people see. Many email platforms use their own return-path domain by default, so SPF passes for them rather than for you. That is why SPF alone does not stop someone spoofing your visible address, and why it works alongside DKIM and DMARC. DMARC requires SPF or DKIM to pass and to align with your From domain.

Two technical limits catch many businesses out. A domain may have only one SPF record; two separate records make SPF fail. And checking the record may involve no more than ten DNS lookups. Every include counts, along with any lookups nested inside it, so a long list of services can quietly break SPF.

Why it matters

SPF is one of the basic signals mailbox providers use to decide whether mail is genuine. At the time of writing (October 2026), Gmail and Yahoo require every sender to have SPF or DKIM, and bulk senders to have both plus DMARC. Without a working record, invoices, quotes and newsletters are more likely to land in spam.

It also helps against impersonation. The UK National Cyber Security Centre recommends that organisations use SPF, DKIM and DMARC together, making it harder for criminals to send convincing fake emails that appear to come from their domain.

Common mistakes

  • Two SPF records, usually because a new tool’s set-up guide said “add this record” and someone did, without merging it into the existing one.
  • More than ten lookups, after years of adding services and never removing old ones.
  • A forgotten sender, such as a booking system, accounting software or the website’s contact form sending as your domain.
  • Switching straight to “-all” before confirming every legitimate sender is listed.
  • Assuming SPF alone protects your domain, without DKIM and DMARC.

How to act on it

List every service that sends email using your domain. Look up your current SPF record with a free DNS lookup tool and compare the two. Merge everything into one record, remove services you no longer use, and check the lookup count. The record is edited wherever your domain’s DNS is hosted, which is often a different company from your website host.

Then check email authentication as a whole: DKIM signing for each sender, and a DMARC record that starts in monitoring mode so you can see who is sending as you before tightening the policy. Getting this right underpins email deliverability, and reviewing it is part of my digital marketing strategy and consulting work.

Do and do not

Do

  • Keep exactly one SPF record
  • List every service that sends as your domain
  • Stay within ten DNS lookups

Do not

  • Add a second SPF record for a new tool
  • Switch to -all before checking every sender
  • Rely on SPF without DKIM and DMARC

Questions people ask about this

Should my SPF record end in ~all or -all?

~all (soft fail) asks receivers to treat unlisted senders with suspicion, while -all (hard fail) asks them to reject such mail. Many businesses start with ~all while they confirm every legitimate sender is included, and rely on DMARC to set the actual enforcement policy. Moving to -all is reasonable once you are confident the list is complete.

Can I have two SPF records?

No. A domain must have exactly one SPF record, and two separate records cause SPF checks to fail. When a new service asks you to add an SPF record, add its include to your existing record instead of creating another.

Does SPF work when emails are forwarded?

Often not. A forwarded message arrives from the forwarding server, which is not on your SPF list, so SPF can fail even for genuine mail. DKIM signatures usually survive forwarding, which is one reason to use both.

Related terms

Found this useful?

Share it, or ask an AI to summarise it

Back to the glossary

Knowing the term is the easy part

Applying it to your own site and budget is the work. Book a call and I will tell you what actually applies to you.