What Is SPF? How to Set Up an SPF Record
SPF (Sender Policy Framework) is a DNS record that lists which servers are allowed to send email for your domain. Receiving mail servers check it to spot forged messages.
How SPF works
When an email arrives, the receiving server looks up the TXT record at your domain that starts with v=spf1. If the sending server is on the list, SPF passes. If not, the final rule (like -all or ~all) tells the receiver how strict to be.
A typical SPF record
This example allows Google Workspace and one email service, and asks receivers to reject anything else:
v=spf1 include:_spf.google.com include:sendgrid.net -all
Common mistakes
Publishing two SPF records. A domain must have only one; two records make SPF fail entirely. Merge them into one line.
Too many lookups. SPF allows at most 10 DNS lookups (include, a, mx, exists, redirect). Every service you add uses some. Remove services you no longer use.
Ending with +all. This lets anyone send as you and defeats the purpose.
Check your record
Run a free audit on DomainGuard to see your SPF record, how many lookups it uses, and whether it ends with a strict rule.
