====== SPF (Sender Policy Framework) ====== **Sender Policy Framework (SPF)** is an email authentication standard that helps prevent email spoofing. It allows a domain owner to publish a list of mail servers that are authorized to send email on behalf of the domain. Receiving mail servers compare the sender's IP address with this list to determine whether the sender is authorized. :contentReference[oaicite:0]{index=0} ----- ===== Why Is SPF Needed? ===== Without SPF, anyone could attempt to send email that appears to come from your domain. For example: From: support@example.com Even if the message was actually sent by an attacker. SPF helps receiving mail servers detect unauthorized senders. ----- ===== How SPF Works ===== SPF is published as a **DNS TXT record**. When an email is received: - The receiving server extracts the **MAIL FROM** (envelope sender) domain. - It retrieves the SPF TXT record from DNS. - It compares the sender's IP address with the authorized servers listed in the SPF record. - The message either passes or fails the SPF check. :contentReference[oaicite:1]{index=1} ----- ===== Example ===== Suppose your domain is: example.com Your SPF record might be: v=spf1 ip4:192.0.2.10 include:_spf.google.com -all Meaning: * Mail may be sent from **192.0.2.10**. * Mail may also be sent by servers authorized in **_spf.google.com**. * Any other sender should fail SPF. ----- ===== SPF Record Syntax ===== Every SPF record begins with: v=spf1 Common mechanisms: ^ Mechanism ^ Meaning ^ | ip4 | Allow an IPv4 address | | ip6 | Allow an IPv6 address | | a | Allow the IP address of the A record | | mx | Allow the domain's MX servers | | include | Include another SPF policy | | exists | Advanced conditional lookup | | all | Matches every sender (used at the end) | ----- ===== The "all" Qualifier ===== The last mechanism is usually **all**. It is normally combined with one of these qualifiers: ^ Ending ^ Meaning ^ | -all | Hard Fail (unauthorized senders should be rejected) | | ~all | Soft Fail (mark as suspicious) | | ?all | Neutral | | +all | Allow everyone (not recommended) | Most domains use: ~all or -all ----- ===== SPF Results ===== Receiving mail servers may report one of these results: ^ Result ^ Meaning ^ | Pass | Sender is authorized | | Fail | Sender is not authorized | | SoftFail | Sender probably unauthorized | | Neutral | No clear decision | | None | No SPF record exists | | TempError | Temporary DNS problem | | PermError | Invalid SPF record | ----- ===== SPF Checks the Envelope Sender ===== A common misunderstanding is that SPF validates the visible **From:** address. It does **not**. SPF authenticates the **MAIL FROM** (also called the **Return-Path** or **envelope sender**) used during SMTP delivery. The visible **From:** header can still be different. This is why SPF alone cannot fully prevent domain spoofing. :contentReference[oaicite:2]{index=2} ----- ===== SPF Lookup Limit ===== An SPF evaluation may perform at most: 10 DNS lookups Mechanisms such as: * include * a * mx * exists * redirect can consume these lookups. If the limit is exceeded, SPF evaluation results in a **PermError**. ----- ===== SPF and Email Forwarding ===== SPF may fail when an email is forwarded. Example: Original sender ↓ Forwarding server ↓ Recipient The forwarding server's IP address is often not listed in the original sender's SPF record. For this reason, SPF is normally combined with **DKIM** and **DMARC**. :contentReference[oaicite:3]{index=3} ----- ===== SPF and Telenegar ===== The **Telenegar Mail Check** service can verify: * Whether an SPF record exists * SPF syntax * Authorized sending mechanisms * Lookup count * Common configuration errors * Final SPF policy (`-all`, `~all`, etc.) This helps improve both email security and deliverability. ----- ===== Common Misconceptions ===== * **SPF encrypts email.** * False. SPF only authorizes sending servers. * **SPF validates the visible From address.** * False. It validates the envelope sender. * **SPF alone stops spoofing.** * False. SPF should be used together with DKIM and DMARC. ----- ===== Best Practices ===== * Publish exactly one SPF TXT record. * Keep the record as simple as possible. * Avoid exceeding the 10-DNS-lookup limit. * End the record with either `~all` or `-all`. * Deploy DKIM and DMARC in addition to SPF. ----- ===== Related Topics ===== * [[email:dns-configuration:dkim|DKIM]] * [[email:dns-configuration:dmarc|DMARC]] * [[networking:dns:dns|DNS Explained]] * [[tools:mailcheck|Mail Check]] ----- {{tag>email spf dns authentication smtp mail security}}