SPF record generator: one correct record for every sender

Tick the services that send email as your domain, add any servers of your own, and copy the SPF record to publish in your DNS. Runs in your browser; nothing is sent anywhere.

Which services send email as your domain?

Using Mailchimp, Klaviyo, HubSpot or Postmark? They send from their own domain or one you set up with them; follow their domain-authentication guide instead of adding an include here.

Your own mail servers
Mail from anywhere else

Add this record at your DNS provider

TypeTXT
Host@
Valuev=spf1 include:_spf.google.com ~all
  • At least 1 of the 10 DNS lookups SPF allows. Included records can use more of their own: after publishing, check the real total with the SPF checker.
  • Host @ means the domain itself. Some DNS providers want the field left empty or the full domain name instead.
  • A domain must have exactly one SPF record. If one already exists, replace it with this one instead of adding a second.

Runs in your browser: nothing you type is sent anywhere.

How to roll it out safely

  1. List every service that sends as your domain: your mailbox provider, newsletters, invoices, the help desk, your app.
  2. Generate the record above and replace your current SPF record with it (keep one record only).
  3. Check it with the SPF checker: the lookup count must stay at 10 or below.
  4. Add a DMARC record with the DMARC generator, starting at p=none, and watch the reports for senders you forgot.

SPF covers the servers. Your reputation also depends on who you send to: mail to dead addresses bounces and hurts it quickly, which is why lists are verified before big sends.

SPF record generator FAQ

Where do I add the SPF record?

At your DNS provider (often your domain registrar or Cloudflare), as a TXT record on the domain itself, usually written as @ in the host field.

I already have an SPF record. Should I add a second one?

No. Two SPF records on one domain is a permanent error and receivers ignore SPF entirely. Merge everything into one record and replace the old one.

Should I use ~all or -all?

Both tell receivers that unlisted servers are not authorised. ~all (soft fail) is the usual choice while you roll out DMARC; -all (fail) is stricter. Avoid ?all and never use +all, which authorises everyone.

Why does the lookup count matter?

SPF allows at most 10 DNS lookups, counting includes inside includes. Past 10, receivers treat SPF as failed. The generator counts the lookups it adds; check the published record with the SPF checker to see the full total.

My email platform is not in the list. What do I do?

Some platforms (Mailchimp, Klaviyo, HubSpot, Postmark and others) send from their own return-path domain or one you set up with them, so your SPF record does not need them. Follow their domain authentication guide. If a platform gave you an include value, paste it in the other includes field.

More free tools

A healthy domain is half of it. Verify the addresses too.

Free credits on sign-up. No card. You only pay for definite answers.

Start free