Free Tool · Runs in your browser

SPF Record Generator

Choose every service that sends mail for your domain, add any custom IPs or includes, pick a failure policy and copy a syntactically valid SPF record with a live lookup-count check.

  • 100% free
  • No signup
  • Nothing leaves your browser

SPF Record Generator

Used in the publishing instructions and to load your current record.

Services that send mail for this domain

One per line or comma separated. CIDR allowed, e.g. 203.0.113.0/24

e.g. 2001:db8::/32

For providers not in the list. Enter the domain only, we add include: for you.

-all tells receivers to reject unlisted senders. ~all marks them suspicious. ?all says nothing.

Your SPF record appears here

Tick at least one sending service, add an IP, or enable the a or mx mechanism to build the record.

How It Works

Three steps, no account needed

  1. 1

    Tick your senders

    Select every service that sends mail from your domain: Google Workspace, Microsoft 365, your ESP, helpdesk and CRM. Add custom IPs if you run your own SMTP.

  2. 2

    Pick a policy

    Choose -all to reject anything unlisted, or ~all while you are still discovering senders. The record and lookup count update as you click.

  3. 3

    Paste into DNS

    Copy the TXT value, publish it on the @ host at your DNS provider, replace any existing v=spf1 record, then verify with the SPF checker.

Record & Asset Generators

What an SPF record does

SPF (Sender Policy Framework) is a TXT record on your domain that lists which servers are allowed to send mail using it in the envelope-from address. When Gmail or Outlook receives a message, it looks up the record and checks whether the connecting IP is covered. A pass feeds into DMARC; a fail, or no record at all, is one of the most common reasons cold email lands in spam.

A record is a single line that starts with v=spf1, followed by mechanisms (ip4, ip6, include, a, mx) and ends with a qualifier on all. The order matters: mechanisms are evaluated left to right and the first match wins.

v=spf1 include:_spf.google.com include:sendgrid.net ip4:203.0.113.10 -all

The 10 DNS lookup limit

RFC 7208 caps SPF at 10 DNS lookups. Every include, a, mx, ptr, exists and redirect counts, and includes pull in whatever their own record references. Google Workspace alone expands to several nested lookups, so a domain with Workspace plus three SaaS tools can hit the ceiling without anyone noticing. Past 10, receivers return permerror and your SPF effectively fails everywhere.

  • Only list services that still send mail. Old ESPs and trial tools are the usual culprits.
  • Prefer ip4 ranges over include when a provider publishes stable IPs, since ip4 costs zero lookups.
  • Marketing and transactional senders often support a dedicated subdomain, which keeps your root record small.
  • Use the SPF checker after publishing to see the real, fully expanded count.

-all, ~all or ?all

The final all mechanism tells receivers what to do with senders you did not list. -all (hard fail) says reject them. ~all (soft fail) says accept but treat as suspicious. ?all (neutral) says nothing, which makes the record almost pointless. For cold email domains, where you control every sender, -all is the right answer and gives DMARC an unambiguous SPF result.

Start with ~all only if you inherited a domain and are unsure what sends from it. Watch DMARC aggregate reports for a couple of weeks, add the legitimate sources, then switch to -all.

Publishing the record correctly

Create one TXT record on the root of the domain (host @ or blank, depending on your DNS provider). If a v=spf1 record already exists, edit it rather than adding another; two SPF records cause a permanent error. Records over 255 characters must be split into multiple quoted strings, which most DNS panels do for you.

Sending subdomains need their own SPF record; they do not inherit the parent's. Propagation is usually quick but can take up to the TTL of the old record. If you buy sending domains through InboxOne, SPF is published for you at provisioning, alongside DKIM and DMARC.

FAQ

Frequently asked questions

Still stuck? Book a 30-minute deliverability call and we'll look at your setup together.

Publish a TXT record on your root domain with the value v=spf1 include:_spf.google.com ~all, or -all once you are confident every sender is listed. If other services also send from the domain, add their include mechanisms to the same record before the all term. Never create a second SPF record.

No. A domain must publish exactly one TXT record starting with v=spf1. If two exist, receivers return permerror and treat SPF as failed. Merge all senders into a single record instead, keeping the total DNS lookups at ten or fewer.

-all is a hard fail: receivers should reject mail from any server not listed. ~all is a soft fail: receivers accept the mail but mark it as suspicious. For domains where you control every sender, such as cold email domains, -all is the stronger choice and works cleanly with DMARC.

The usual reasons are more than ten DNS lookups, a typo in the include hostname, two SPF records on the domain, or the provider sending from a subdomain that has no record. Run the SPF checker on the exact From domain to see the expanded chain and the failing term.

Yes. Gmail and Yahoo require both SPF and DKIM for bulk senders, and DMARC needs at least one of them to align. SPF also protects the envelope-from address used for bounces, which DKIM does not cover. Set up all three on every sending domain.

Yes. The record is assembled in your browser and nothing is sent to our servers. The optional Check existing button queries public DNS-over-HTTPS resolvers directly from your browser. There is no signup and no limit on how many records you build.

Ready to Scale Your Outbound?

Your Cold Email Infrastructure Shouldn't Be the Bottleneck.

Domains, mailboxes, DNS, deliverability, and platform exports — all from one dashboard. Starting at $39/month for 10 production-ready mailboxes.

Inbox One Logo

Cold email infrastructure platform. Buy domains, provision Google Workspace mailboxes, auto-configure DNS, and export to 5 outreach platforms — all from one dashboard.

© 2026 InboxOne. All rights reserved.