A single SPF record per domain
Two v=spf1 records make SPF fail for every email. Adding a service means editing the record you have, not adding another.
Tick the services that send email as your domain. You get a single valid record, the lookup count, and the mistakes to avoid.
~all is the safe default while DMARC decides what happens to failures; -all once you're sure every sender is listed.
v=spf1 include:_spf.google.com ~all1 of 10 lookups at the top level; each provider's record can add more. Check the total once it's published.
Replace any existing SPF record — a domain may have only one. Once it's live, check the real lookup count.
A receiving server looks up the SPF record of the domain in the envelope sender and checks the sending server is on the list.
Two v=spf1 records make SPF fail for every email. Adding a service means editing the record you have, not adding another.
Each include, a, mx and redirect costs a DNS lookup, and so do the includes inside them. Past ten, receivers return an error and SPF fails.
~all marks other servers as suspicious, -all says reject them. With DMARC in place, ~all is enough — DMARC decides what happens.
Forwarded mail arrives from a server that isn't on your list. That's why DKIM and DMARC matter: Gmail and Yahoo want both SPF and DKIM from bulk senders.
Read more: SPF, DKIM and DMARC explained · DMARC generator
Mailbase writes SPF, DKIM, DMARC and the reply MX when you add or buy a domain, then raises its volume only while real bounces and complaints stay low.