SPF record builder
Select every service that sends email on your behalf. We build the record and count its lookups as you go.
How to build a correct SPF record
- Start from your current record if you have one, so nothing already listed is lost.
- Pick your email provider (Microsoft 365, Google Workspace, Zoho and so on).
- Add every other service that sends email using your domain: newsletters, invoicing and accounting tools, help desks, CRMs and website forms. Ask finance, sales and marketing; they often use services IT doesn’t know about.
- Watch the lookup counter. SPF allows 10 DNS lookups. The builder counts them live, including the lookups hidden inside each service’s include.
- Choose the ending.
~allmarks unlisted senders as suspicious and is the safe choice while you set up DMARC;-allrejects them. - Publish one record only, replacing the old one, then confirm it with the SPF checker.
When you hit the 10-lookup limit
Remove services you no longer use, drop a and mx if all your email goes through a provider, or move bulk email to a subdomain with its own SPF record. Our guide to fixing “too many DNS lookups” explains each option. Remember that many sending services pass DMARC through DKIM rather than SPF, so check whether a service needs an SPF include at all before adding one.