SPF Record Generator

Create a correct SPF record for your domain without memorizing RFC 7208 syntax. List your sending sources, choose how strictly unlisted senders are treated, and copy a ready-to-publish TXT record.

Build your SPF record

List every server and service allowed to send email as your domain, choose a policy, and get a ready-to-publish TXT record.

Where the record will be published. Optional — leave empty to use the generic host "@".

Authorized IP addresses and ranges

IPv4 or IPv6 addresses, or CIDR ranges such as 192.0.2.0/24, of servers you operate.

Include domains

One entry per third-party service that sends mail as your domain, e.g. its SPF include host.

Domain servers

Authorize the hosts already named in your domain's DNS. Each option costs DNS lookups when receivers evaluate your record.

Delegate this domain's entire SPF policy to another domain's record. A redirect replaces the policy options below and cannot be combined with an all mechanism.

Policy for unlisted senders

What receivers should do with mail from servers you did not list above.

Everything runs in your browser. The values you enter are never sent to a server or stored.

How the SPF Record Generator works

List your sending sources

Add the IP addresses or ranges of servers you operate and an include entry for every third-party service that sends mail as your domain. Optionally authorize your domain's A or MX hosts.

Choose a policy

Decide what receivers do with senders you did not list: soft fail (~all) while testing, fail (-all) when strict, or a redirect if another domain owns the whole policy.

Generate and review

The record is built deterministically, deduplicated, and checked against the same RFC 7208 parser our checker tools use — including the 10 DNS lookup limit and record length guidance.

Publish one TXT record

Add the value to your DNS provider at the host shown. If an SPF record already exists, merge into it — never publish a second v=spf1 record.

Verify after publishing

Once DNS propagates, run your domain through the SPF Record Checker to confirm the published record and the true nested lookup count.

What this tool does and does not tell you

  • The lookup estimate covers only the record you build here. Included records can spend further lookups, and only a live SPF check can measure that total.
  • A valid SPF record does not guarantee inbox placement. Receivers also weigh DKIM, DMARC alignment, reputation, and content.
  • The generator builds the record but publishes nothing; you must add it to your DNS provider yourself.
  • The deprecated ptr mechanism and the unsafe +all qualifier are deliberately not offered.
  • Static generation cannot tell you whether a specific message will pass SPF — that depends on the sending IP and the MAIL FROM/HELO identity used at send time.

Related free tools

SPF Record Checker

Look up a live domain, expand nested includes, and verify the real DNS lookup count of your published record.

Open tool

SPF Raw Checker

Paste any SPF record text and validate its syntax, mechanisms, and policy without a DNS lookup.

Open tool

DKIM Record Generator

Create a DKIM key pair and DNS record so your outgoing mail carries a cryptographic signature.

Open tool

DMARC Record Generator

Build a DMARC policy that ties SPF and DKIM to your visible From domain and requests reports.

Open tool

Frequently Asked Questions

What is an SPF record?

An SPF (Sender Policy Framework) record is a single TXT record published in your domain's DNS that lists which servers and services are allowed to send email as your domain. Receiving mail servers check it to decide how to treat messages from unlisted sources.

Should I choose ~all, -all, or ?all?

Start with ~all (soft fail): unlisted senders are flagged but still delivered, which is forgiving while you confirm your sender list. Move to -all (fail) once you are confident every legitimate sender is included. ?all (neutral) makes no statement and gives you no spoofing protection, so this tool warns whenever you pick it. We never offer +all, because it authorizes every server on the internet.

Can I publish more than one SPF record?

No. A domain must have exactly one TXT record starting with v=spf1. If one already exists — for example from an email provider setup — merge the new mechanisms into that record instead of adding a second one. Two SPF records cause a permanent error and your policy stops working entirely.

What is the 10 DNS lookup limit?

RFC 7208 limits SPF evaluation to 10 DNS-querying mechanisms and modifiers (include, a, mx, ptr, exists, and redirect). Receivers return a permanent error once the limit is exceeded, which can make legitimate mail fail. This generator counts the direct lookups in your record, but included records can spend more — always verify the live total with an SPF checker after publishing.

Does a valid SPF record guarantee inbox placement?

No. SPF only tells receivers which servers may send as your domain. Inbox placement also depends on DKIM signing, DMARC alignment, sender reputation, and content. Treat SPF as one required layer, not a deliverability guarantee.

Why is there no ptr option?

The ptr mechanism is deprecated by RFC 7208 (section 5.5) because it is slow and unreliable to evaluate, so this generator deliberately does not offer it. List explicit ip4/ip6 addresses or use include instead.

Increase Your Sales Right Now

Automate Sales Outreach & Get Booked!

Start Free Trial

(14 Day Free Trial, No CC Required)