What an SPF record does
SPF (Sender Policy Framework) is a TXT record on your domain that lists which servers are allowed to send mail using it in the envelope-from address. When Gmail or Outlook receives a message, it looks up the record and checks whether the connecting IP is covered. A pass feeds into DMARC; a fail, or no record at all, is one of the most common reasons cold email lands in spam.
A record is a single line that starts with v=spf1, followed by mechanisms (ip4, ip6, include, a, mx) and ends with a qualifier on all. The order matters: mechanisms are evaluated left to right and the first match wins.
v=spf1 include:_spf.google.com include:sendgrid.net ip4:203.0.113.10 -allThe 10 DNS lookup limit
RFC 7208 caps SPF at 10 DNS lookups. Every include, a, mx, ptr, exists and redirect counts, and includes pull in whatever their own record references. Google Workspace alone expands to several nested lookups, so a domain with Workspace plus three SaaS tools can hit the ceiling without anyone noticing. Past 10, receivers return permerror and your SPF effectively fails everywhere.
- Only list services that still send mail. Old ESPs and trial tools are the usual culprits.
- Prefer ip4 ranges over include when a provider publishes stable IPs, since ip4 costs zero lookups.
- Marketing and transactional senders often support a dedicated subdomain, which keeps your root record small.
- Use the SPF checker after publishing to see the real, fully expanded count.
-all, ~all or ?all
The final all mechanism tells receivers what to do with senders you did not list. -all (hard fail) says reject them. ~all (soft fail) says accept but treat as suspicious. ?all (neutral) says nothing, which makes the record almost pointless. For cold email domains, where you control every sender, -all is the right answer and gives DMARC an unambiguous SPF result.
Start with ~all only if you inherited a domain and are unsure what sends from it. Watch DMARC aggregate reports for a couple of weeks, add the legitimate sources, then switch to -all.
Publishing the record correctly
Create one TXT record on the root of the domain (host @ or blank, depending on your DNS provider). If a v=spf1 record already exists, edit it rather than adding another; two SPF records cause a permanent error. Records over 255 characters must be split into multiple quoted strings, which most DNS panels do for you.
Sending subdomains need their own SPF record; they do not inherit the parent's. Propagation is usually quick but can take up to the TTL of the old record. If you buy sending domains through InboxOne, SPF is published for you at provisioning, alongside DKIM and DMARC.

