Contact
All free tools

SPF record builder

Build a draft SPF record by ticking the services that send your mail. The builder counts its DNS lookups against the limit of 10, and you check it covers every sender before you publish it.

  • include
  • ip4
  • ip6
  • mx
  • a
  • -all
  • ~all

Build your SPF record

It runs in your browser. The only thing it asks the internet is the public SPF records of the services you choose, to count their lookups.

SPF record builderRuns in your browser

About this builder

List every sender, then close the door

One SPF record names every service allowed to send mail as your domain, and says what to do with the rest.

Which services should you tick?

Tick every service that sends mail with your domain in the From address: your mailbox provider, and any newsletter, invoicing or support system that sends as you. Leave out a service and its mail starts failing SPF. Mailchimp's newsletters are an exception: Mailchimp's own setup guide asks for DKIM and DMARC records, not an SPF change.

Should the record end with -all or ~all?

Use -all once every sender is listed: mail from anywhere else fails SPF, and most receivers reject it. Use ~all while you are still finding your senders: that mail only soft-fails.

Microsoft recommends -all for Microsoft 365 domains, and Google recommends ~all. Either works well once DMARC is in place, because DMARC decides what happens to failing mail.

Why does it count lookups?

SPF allows at most 10 DNS lookups for a record, counting the records it includes and theirs in turn (RFC 7208). A record that needs more is treated as broken, and your mail fails SPF everywhere. The builder follows each service's record in public DNS and refuses a combination that goes over.

Where do the values come from?

Each value comes from the provider's own documentation, read on 26 September 2026.

include:_spf.google.com
Google Workspace
include:spf.host-h.net
xneelo mail hosting
include:spf.mandrillapp.com
Mailchimp Transactional (Mandrill)
include:sendgrid.net
Twilio SendGrid

Amazon SES is not in the list on purpose. Its include:amazonses.com belongs on a separate custom MAIL FROM subdomain, with its own MX record, and never on your main domain.

Some providers publish no fixed value. Afrihost, for example, has its control panel write one for your server. For those, copy the value your provider's panel shows into the field for anything else.

Is anything you choose sent to us?

No. The builder writes the record in your browser. It asks Cloudflare's public DNS service for the records your draft refers to, including any you add yourself, to count their lookups. It stores nothing and sends nothing to us. The page shows no ads.

Want it published for you?

Send us the record you built, or tell us what is going wrong with your mail. We'll tell you plainly what it takes to fix, before any work starts.