email:spf
Table of Contents
SPF — Sender Policy Framework
SPF (Sender Policy Framework) is an email authentication method that prevents spammers from sending emails using your domain.
What is SPF?
SPF allows domain owners to specify which mail servers are authorized to send emails on their behalf.
When a receiving mail server gets an email, it checks:
1. The envelope sender domain (Return-Path) 2. The IP address of the sending server 3. The SPF record published by the domain owner 4. If the IP is authorized, SPF passes; otherwise, it fails
SPF Record Format
An SPF record is a TXT record published in the domain's DNS:
example.com. TXT “v=spf1 include:_spf.google.com ~all”
Components:
| Component | Description |
|---|---|
| v=spf1 | Version (must be exactly this) |
| Mechanisms | Who is allowed to send |
| Qualifier | What to do with unauthorized senders |
SPF Mechanisms
| Mechanism | Meaning |
|---|---|
| `a` | The domain's A record IP address |
| `mx` | The domain's MX record IP addresses |
| `include` | Include SPF records from another domain |
| `ip4` | A specific IPv4 address |
| `ip6` | A specific IPv6 address |
| `ptr` | PTR record (reverse lookup) |
| `exists` | Check if a domain exists |
| `all` | Everything else (catch-all) |
SPF Qualifiers
| Qualifier | Meaning |
|---|---|
| + | Pass — authorized (default) |
| - | Fail — hard fail (reject) |
| ~ | Soft Fail — mark as spam |
| ? | Neutral — no policy |
Common SPF Examples
Google Workspace (Gmail):
v=spf1 include:_spf.google.com ~all
Microsoft 365:
v=spf1 include:spf.protection.outlook.com ~all
Custom (self-hosted):
v=spf1 a mx ip4:192.168.1.0/24 ~all
SPF Lookup Limits
SPF has a hard limit of 10 DNS lookups. If you exceed this, receivers may reject your email.
Lookup mechanisms:
- include
- a
- mx
- ptr
- exists
- redirect
SPF Policy Levels
| Level | Policy | Description |
|---|---|---|
| Strong | `-all` | Hard fail — unlisted senders are rejected |
| Moderate | `~all` | Soft fail — unlisted senders go to spam |
| Weak | `?all` | Neutral — no policy applied |
| Dangerous | `+all` | Pass all — effectively no protection |
Test Your SPF
email/spf.txt · Last modified: by 127.0.0.1
