Skip to content
Back to Glossary

Authentication

Updated

SPF (Sender Policy Framework)

Definition

SPF (Sender Policy Framework) is a DNS TXT record that lists which servers may send email using a domain in the envelope sender (Return-Path). Receivers compare the connecting server's IP against that list and record pass, fail, softfail or neutral.

How it works

SPF is defined in RFC 7208. When a server receives a message, it reads the domain in the SMTP MAIL FROM command (the envelope sender, which ends up in the Return-Path header) and looks up the TXT record starting with v=spf1 on that domain.

The record is read left to right. Mechanisms such as ip4, ip6, a, mx and include either match the connecting IP or move on. The first match decides the result, and the final all mechanism sets what happens to everything else: -all means fail, ~all means softfail, ?all means neutral.

SPF does not check the visible From address. A message can pass SPF for a bounce domain like ses.example.com while showing From: [email protected]. That gap is why DMARC adds alignment: the SPF-authenticated domain must match the From domain.

Example

SPF TXT record
example.com. TXT "v=spf1 include:_spf.google.com include:amazonses.com ~all"

Google Workspace and Amazon SES may send for example.com. Anything else gets a softfail.

Why it matters

Since February 2024, Gmail and Yahoo require every sender to authenticate with SPF or DKIM, and bulk senders (around 5,000+ messages a day to Gmail) to have both, plus DMARC. Unauthenticated mail is rate limited or rejected.

SPF is also one of the two ways a message can pass DMARC. Without an aligned SPF pass, DMARC depends entirely on DKIM.

Best practices

  • Publish exactly one v=spf1 record per hostname. Two SPF records is a permanent error, and receivers treat it like no SPF at all.
  • Stay under 10 DNS lookups. include, a, mx, ptr, exists and redirect each count, including nested includes. Going over returns permerror.
  • Start with ~all while you inventory senders, then move to -all once every legitimate source is listed. DMARC enforcement matters more than the SPF qualifier.
  • Remove includes for tools you no longer use. Each one widens who can pass SPF for your domain.
  • Remember that forwarding breaks SPF, because the forwarder's IP is not in your record. DKIM survives forwarding, so never rely on SPF alone.

How Lumail handles SPF

Lumail sends through Amazon SES with a custom MAIL FROM domain, ses.your-domain.com. You add an SPF TXT record (v=spf1 include:amazonses.com ~all) and an MX record on that subdomain, so SPF passes and aligns with your From domain under DMARC's relaxed alignment.

Lumail checks these records when you add a domain during onboarding and on the domain page. Sending to your audience unlocks automatically once the records verify.

Check a real message with the free mail tester or the spam tester.

Frequently asked questions

What is the SPF 10 DNS lookup limit?

RFC 7208 caps SPF evaluation at 10 mechanisms that need a DNS query (include, a, mx, ptr, exists and the redirect modifier), counting nested includes. Exceeding it returns a permanent error, so the record fails to authenticate anything.

Should I use ~all or -all?

Both are valid. ~all (softfail) is the safer default while you confirm every sender. -all (fail) is stricter. Under DMARC, the DMARC policy decides what happens to failing mail, so p=quarantine or p=reject protects you more than the SPF qualifier does.

Can a domain have two SPF records?

No. More than one v=spf1 record on the same hostname is a permerror. Merge all senders into a single record with multiple include mechanisms.

Does SPF protect the From address people see?

Not by itself. SPF checks the envelope sender (Return-Path). DMARC is what ties the SPF result to the visible From domain through alignment.

Related terms, tools and docs

Browse every definition in the email marketing glossary.

Send your next email with Lumail.

3,000 emails a month free. Unlimited subscribers on every plan. Campaigns, automations and transactional email on one domain.