SMTP Email Proxy for Cold Email Outreach|All updates
DNS & auth

Free SPF Generator

Generate a correctly formatted SPF record for your domain.

Use ~all (soft fail) while configuring; switch to -all (hard fail) once all senders are confirmed.

Include the domain's MX records as authorised senders.

Include the domain's A record as an authorised sender.

Comma-separated — e.g. _spf.google.com, _spf.mailchimp.com

Comma-separated — e.g. 203.0.113.10, 198.51.100.0/24

Comma-separated — e.g. 2001:db8::1

Comma-separated — e.g. mail.example.com

Fetch the current SPF record and merge new entries into it.

01 · Definition

What is spf generator?

An SPF generator builds a Sender Policy Framework record — the v=spf1 TXT record that tells receiving mail servers which IPs and hostnames are authorised to send mail on behalf of your domain. Creating a correctly formatted SPF record from scratch is error-prone: the mechanisms must appear in the right order, DNS-lookup-consuming mechanisms count toward an RFC 7208 limit of ten, and the qualifier at the end determines whether unauthorised senders are rejected or merely soft-failed.

The tool above takes your domain, senders and policy choice and assembles a correctly formatted record in one step. Add your MX servers, authorised IPs, and third-party ESP include: mechanisms, pick your policy qualifier, and the generator outputs a v=spf1 string ready to publish in DNS. Read the SPF generator guide for a full walkthrough of record syntax, DNS lookup budgeting, and how to roll out SPF alongside DMARC.

02 · Process

How it works

  1. 1Enter your domain.The generated record will be published as a TXT entry at the apex of this domain — the same domain that appears in your envelope sender (MAIL FROM).
  2. 2Add your sending sources.Toggle MX and A-record senders on, paste comma-separated IPs or CIDR blocks for dedicated sending servers, add hostnames for any a:hostname mechanisms, and list third-party ESP domains (e.g. _spf.google.com) as include: entries.
  3. 3Choose a policy qualifier.~all (soft fail) is safe to start with while you are still discovering senders. Switch to -all (hard fail) once your DMARC policy is at p=quarantine or p=reject and you are confident every legitimate sender is covered.
  4. 4Review the DNS lookup count.RFC 7208 caps SPF at 10 DNS-lookup-consuming mechanisms per evaluation. Each include:, a, mx, exists: and redirect: counts as one lookup. The generator estimates the direct lookup count and warns if you approach or exceed the limit.
  5. 5Publish the record in DNS.Copy the generated v=spf1 string and add it as a TXT record at your domain apex. Allow up to 48 hours for DNS propagation, then verify with the SPF lookup tool.

03 · Risk

Why it matters

SPF is the first layer of the email-authentication baseline. Without it, any sender on the internet can forge your domain in the envelope sender and pass basic delivery checks on many mailbox providers. A correctly configured SPF record — paired with DKIM and DMARC — closes that door.

For regulated firms, SPF misconfiguration is a compliance risk. Mailbox providers may junk or reject unauthenticated mail, the customer never sees it, and the firm has no audit trail of what was actually delivered. The FCA forced 19,766 financial promotions to be amended or withdrawn in 2024 — a 97.5% increase from 2023 — making sender-authentication hygiene part of the evidence regulators expect to see.

19,766 financial promotions amended or withdrawn
UK FCA enforcement actions, 2024 — a 97.5% increase from 2023.

04 · Use cases

Common ways to use this tool

  • New domain setup. Before the first send from a new domain, generate and publish an SPF record so receivers have a valid policy to evaluate from day one.
  • Adding a new ESP. When onboarding a new email service provider, add their include: domain and regenerate to confirm the lookup count hasn't pushed you over ten.
  • DMARC rollout. SPF must pass and align before you can move DMARC from p=none to p=quarantine or p=reject. Generate and verify SPF first, then tighten DMARC.
  • Mergers and migrations. When two brands consolidate infrastructure, regenerate the combined SPF record to include every sending source from both organisations without exceeding the lookup limit.

05 · Interpretation

What to check in the result

Before publishing the generated record, confirm these four things:

  • DNS lookup count is under 10. The generator estimates direct lookups. If the count is 7 or above, consider flattening include: chains — each nested include: also consumes lookups during live evaluation.
  • Every legitimate sender is listed. Marketing ESPs, transactional providers, billing platforms, payroll systems, calendar invites — any service that sends mail as your domain must appear via ip4:, ip6:, a: or include:. A missing sender silently fails SPF for those messages.
  • Policy qualifier matches your DMARC phase. Use ~all while DMARC is at p=none (monitoring). Switch to -all once DMARC is enforcing and you have confirmed all senders. Never use +all in production.
  • Only one SPF record at the domain apex. Publishing two v=spf1 TXT records at the same domain causes an immediate permerror for every receiver. Merge all mechanisms into a single record.

Frequently asked

Questions about this tool

Copyright © 2026 - Jonah and Associates Pty Ltd