📧 SPF Record Builder

Enter includes (mail providers), IPv4/IPv6 ranges and a fail policy to build a valid SPF TXT record. Publish the result as a TXT record on your domain's apex.

How the record is ordered

The builder works entirely in your browser - it publishes nothing and resolves nothing. It splits each box on commas, drops empty entries, and emits the mechanisms in a fixed order: version, IPv4, IPv6, includes, then the policy term last.

v=spf1 ip4:203.0.113.10 include:_spf.google.com include:sendgrid.net -all

That order is not cosmetic. SPF is evaluated left to right and the first match wins, so cheap ip4 mechanisms are tested before any include triggers a DNS query. The all term must be last - anything after it is ignored.

The lookup budget and the fail policy

Receivers permit ten DNS lookups per evaluation. Every include: costs one, ip4: and ip6: cost nothing, and the count follows nested records too. The warning here counts only the includes you typed, so the two above show as 2 while _spf.google.com on its own expands to four lookups. Check the real total with the SPF Checker before publishing; going over ten produces permerror, which receivers treat as a failure.

-allHard fail. Unlisted senders are unauthorised and may be rejected.
~allSoft fail. Accept but treat as suspect - the safer setting while you are still finding senders.
?allNeutral. States nothing, which is close to having no record.
+allAuthorises every host on the internet. Never publish this.
SPF is checked against the envelope Return-Path, not the From: address your reader sees, and it breaks when mail is forwarded. Neither -all nor a perfect record can promise inbox placement on its own.

Frequently asked questions

Should I use -all or ~all?

Start with ~all until aggregate reports show every legitimate sender listed, then switch to -all. Publishing a hard fail before you have found a forgotten billing system or CRM is how real mail gets rejected.

Do IP addresses count toward the ten lookup limit?

No. ip4 and ip6 mechanisms are matched directly with no query, which is exactly why replacing a heavy include with the vendor's published ranges is the standard way to get back under the limit.

Where does the SPF record go in DNS?

On the domain itself as a TXT record - the apex for example.com, or the subdomain name if that subdomain sends its own mail. Only one v=spf1 record per name is allowed.