SPF record generator: one correct record for every sender
Tick the services that send email as your domain, add any servers of your own, and copy the SPF record to publish in your DNS. Runs in your browser; nothing is sent anywhere.
Add this record at your DNS provider
TXT@v=spf1 include:_spf.google.com ~all- At least 1 of the 10 DNS lookups SPF allows. Included records can use more of their own: after publishing, check the real total with the SPF checker.
- Host @ means the domain itself. Some DNS providers want the field left empty or the full domain name instead.
- A domain must have exactly one SPF record. If one already exists, replace it with this one instead of adding a second.
Runs in your browser: nothing you type is sent anywhere.
How to roll it out safely
- List every service that sends as your domain: your mailbox provider, newsletters, invoices, the help desk, your app.
- Generate the record above and replace your current SPF record with it (keep one record only).
- Check it with the SPF checker: the lookup count must stay at 10 or below.
- Add a DMARC record with the DMARC generator, starting at p=none, and watch the reports for senders you forgot.
SPF covers the servers. Your reputation also depends on who you send to: mail to dead addresses bounces and hurts it quickly, which is why lists are verified before big sends.
SPF record generator FAQ
Where do I add the SPF record?
At your DNS provider (often your domain registrar or Cloudflare), as a TXT record on the domain itself, usually written as @ in the host field.
I already have an SPF record. Should I add a second one?
No. Two SPF records on one domain is a permanent error and receivers ignore SPF entirely. Merge everything into one record and replace the old one.
Should I use ~all or -all?
Both tell receivers that unlisted servers are not authorised. ~all (soft fail) is the usual choice while you roll out DMARC; -all (fail) is stricter. Avoid ?all and never use +all, which authorises everyone.
Why does the lookup count matter?
SPF allows at most 10 DNS lookups, counting includes inside includes. Past 10, receivers treat SPF as failed. The generator counts the lookups it adds; check the published record with the SPF checker to see the full total.
My email platform is not in the list. What do I do?
Some platforms (Mailchimp, Klaviyo, HubSpot, Postmark and others) send from their own return-path domain or one you set up with them, so your SPF record does not need them. Follow their domain authentication guide. If a platform gave you an include value, paste it in the other includes field.
More free tools
- MX lookup
See a domain's mail servers and which provider runs them.
- SPF checker
Check the SPF record, its DNS lookup count and the all mechanism.
- DMARC checker
Read the DMARC policy, reporting address and what to tighten.
- DKIM checker
Find a domain's DKIM keys and check their length and status.
- BIMI checker
See whether inboxes can show your logo, and what is missing.
- Disposable email checker
Find out if a domain is a throwaway inbox service.
- DMARC record generator
Create a DMARC record, from monitoring to full protection.
- Free email verifier
Check whether one address actually exists, with a live mailbox check.
A healthy domain is half of it. Verify the addresses too.
Free credits on sign-up. No card. You only pay for definite answers.
Start free