SPF (Sender Policy Framework) is an email authentication standard that lets a domain owner publish a list of the servers allowed to send email on its behalf. Receiving mail servers check that list, and mail from a server that is not on it is more likely to be rejected or sent to spam.
How SPF works
SPF lives in a single TXT record in your domain’s DNS. A business using Microsoft 365 for staff email and a separate platform for newsletters might publish something like this, where the second include stands in for the value your email platform gives you:
v=spf1 include:spf.protection.outlook.com include:mail.example-platform.com ~all
Reading left to right: “v=spf1” marks the record as SPF; each “include” adds a provider’s servers; “~all” tells receivers to treat anything else with suspicion, which is called a soft fail. “-all” is a hard fail, asking receivers to reject unlisted senders outright.
The check is made against the domain in the hidden return path, also called the envelope sender, not the “From” address people see. Many email platforms use their own return-path domain by default, so SPF passes for them rather than for you. That is why SPF alone does not stop someone spoofing your visible address, and why it works alongside DKIM and DMARC. DMARC requires SPF or DKIM to pass and to align with your From domain.
Two technical limits catch many businesses out. A domain may have only one SPF record; two separate records make SPF fail. And checking the record may involve no more than ten DNS lookups. Every include counts, along with any lookups nested inside it, so a long list of services can quietly break SPF.
Why it matters
SPF is one of the basic signals mailbox providers use to decide whether mail is genuine. At the time of writing (October 2026), Gmail and Yahoo require every sender to have SPF or DKIM, and bulk senders to have both plus DMARC. Without a working record, invoices, quotes and newsletters are more likely to land in spam.
It also helps against impersonation. The UK National Cyber Security Centre recommends that organisations use SPF, DKIM and DMARC together, making it harder for criminals to send convincing fake emails that appear to come from their domain.
Common mistakes
- Two SPF records, usually because a new tool’s set-up guide said “add this record” and someone did, without merging it into the existing one.
- More than ten lookups, after years of adding services and never removing old ones.
- A forgotten sender, such as a booking system, accounting software or the website’s contact form sending as your domain.
- Switching straight to “-all” before confirming every legitimate sender is listed.
- Assuming SPF alone protects your domain, without DKIM and DMARC.
How to act on it
List every service that sends email using your domain. Look up your current SPF record with a free DNS lookup tool and compare the two. Merge everything into one record, remove services you no longer use, and check the lookup count. The record is edited wherever your domain’s DNS is hosted, which is often a different company from your website host.
Then check email authentication as a whole: DKIM signing for each sender, and a DMARC record that starts in monitoring mode so you can see who is sending as you before tightening the policy. Getting this right underpins email deliverability, and reviewing it is part of my digital marketing strategy and consulting work.
