01 · Definition
What is spf generator?
An SPF generator builds a Sender Policy Framework record — the v=spf1 TXT record that tells receiving mail servers which IPs and hostnames are authorised to send mail on behalf of your domain. Creating a correctly formatted SPF record from scratch is error-prone: the mechanisms must appear in the right order, DNS-lookup-consuming mechanisms count toward an RFC 7208 limit of ten, and the qualifier at the end determines whether unauthorised senders are rejected or merely soft-failed.
The tool above takes your domain, senders and policy choice and assembles a correctly formatted record in one step. Add your MX servers, authorised IPs, and third-party ESP include: mechanisms, pick your policy qualifier, and the generator outputs a v=spf1 string ready to publish in DNS. Read the SPF generator guide for a full walkthrough of record syntax, DNS lookup budgeting, and how to roll out SPF alongside DMARC.
02 · Process
How it works
- 1Enter your domain.The generated record will be published as a TXT entry at the apex of this domain — the same domain that appears in your envelope sender (
MAIL FROM). - 2Add your sending sources.Toggle MX and A-record senders on, paste comma-separated IPs or CIDR blocks for dedicated sending servers, add hostnames for any
a:hostnamemechanisms, and list third-party ESP domains (e.g._spf.google.com) asinclude:entries. - 3Choose a policy qualifier.
~all(soft fail) is safe to start with while you are still discovering senders. Switch to-all(hard fail) once your DMARC policy is atp=quarantineorp=rejectand you are confident every legitimate sender is covered. - 4Review the DNS lookup count.RFC 7208 caps SPF at 10 DNS-lookup-consuming mechanisms per evaluation. Each
include:,a,mx,exists:andredirect:counts as one lookup. The generator estimates the direct lookup count and warns if you approach or exceed the limit. - 5Publish the record in DNS.Copy the generated
v=spf1string and add it as a TXT record at your domain apex. Allow up to 48 hours for DNS propagation, then verify with the SPF lookup tool.
03 · Risk
Why it matters
SPF is the first layer of the email-authentication baseline. Without it, any sender on the internet can forge your domain in the envelope sender and pass basic delivery checks on many mailbox providers. A correctly configured SPF record — paired with DKIM and DMARC — closes that door.
For regulated firms, SPF misconfiguration is a compliance risk. Mailbox providers may junk or reject unauthenticated mail, the customer never sees it, and the firm has no audit trail of what was actually delivered. The FCA forced 19,766 financial promotions to be amended or withdrawn in 2024 — a 97.5% increase from 2023 — making sender-authentication hygiene part of the evidence regulators expect to see.
04 · Use cases
Common ways to use this tool
- New domain setup. Before the first send from a new domain, generate and publish an SPF record so receivers have a valid policy to evaluate from day one.
- Adding a new ESP. When onboarding a new email service provider, add their
include:domain and regenerate to confirm the lookup count hasn't pushed you over ten. - DMARC rollout. SPF must pass and align before you can move DMARC from
p=nonetop=quarantineorp=reject. Generate and verify SPF first, then tighten DMARC. - Mergers and migrations. When two brands consolidate infrastructure, regenerate the combined SPF record to include every sending source from both organisations without exceeding the lookup limit.
05 · Interpretation
What to check in the result
Before publishing the generated record, confirm these four things:
- DNS lookup count is under 10. The generator estimates direct lookups. If the count is 7 or above, consider flattening
include:chains — each nestedinclude:also consumes lookups during live evaluation. - Every legitimate sender is listed. Marketing ESPs, transactional providers, billing platforms, payroll systems, calendar invites — any service that sends mail as your domain must appear via
ip4:,ip6:,a:orinclude:. A missing sender silently fails SPF for those messages. - Policy qualifier matches your DMARC phase. Use
~allwhile DMARC is atp=none(monitoring). Switch to-allonce DMARC is enforcing and you have confirmed all senders. Never use+allin production. - Only one SPF record at the domain apex. Publishing two
v=spf1TXT records at the same domain causes an immediatepermerrorfor every receiver. Merge all mechanisms into a single record.