Free tool · SPF generator

One SPF record, done right.

Tick the services that send email as your domain. You get a single valid record, the lookup count, and the mistakes to avoid.

Services that send email as your domain
The domain's own servers
Everything else

~all is the safe default while DMARC decides what happens to failures; -all once you're sure every sender is listed.

TypeTXTHost / name@(the domain itself)
v=spf1 include:_spf.google.com ~all

1 of 10 lookups at the top level; each provider's record can add more. Check the total once it's published.

Replace any existing SPF record — a domain may have only one. Once it's live, check the real lookup count.

01How SPF works

One record that lists who may send as you.

A receiving server looks up the SPF record of the domain in the envelope sender and checks the sending server is on the list.

Only one

A single SPF record per domain

Two v=spf1 records make SPF fail for every email. Adding a service means editing the record you have, not adding another.

10 lookups

A hard limit on includes

Each include, a, mx and redirect costs a DNS lookup, and so do the includes inside them. Past ten, receivers return an error and SPF fails.

~all or -all

What happens to everyone else

~all marks other servers as suspicious, -all says reject them. With DMARC in place, ~all is enough — DMARC decides what happens.

Not enough alone

SPF doesn't survive forwarding

Forwarded mail arrives from a server that isn't on your list. That's why DKIM and DMARC matter: Gmail and Yahoo want both SPF and DKIM from bulk senders.

Read more: SPF, DKIM and DMARC explained · DMARC generator

02Questions

What people ask.

Do I need an include for my newsletter tool?
Only if it sends with your domain in the envelope (return-path). Most marketing platforms — Mailchimp, Postmark and others — use their own return-path and authenticate you through DKIM instead, so an include just wastes a lookup. Their setup page says which records they need.
Where do I put the record?
At your DNS host (OVHcloud, Gandi, Cloudflare, IONOS…), as a TXT record on the domain itself — the host is “@” or left empty. If an SPF record already exists, replace it.
~all or -all?
Start with ~all. Once DMARC reports show every service you use passing, -all is safe — but with a DMARC policy of quarantine or reject, the difference barely matters.
How do I know the real lookup count?
The generator counts the lookups it adds; each provider's own record can add more. Publish the record, then run the free domain check: it follows every include and gives the total.
03Free tools

More free tools.

Deliverability, handled

Records right. Domain warmed. Then send.

Mailbase writes SPF, DKIM, DMARC and the reply MX when you add or buy a domain, then raises its volume only while real bounces and complaints stay low.