InfraNestInfraNest

Free tool

SPF Record Generator

Start from the SPF record your domain already publishes, add the services that send for you, and see what it costs against the ten-lookup limit before you publish it.

Try:

Go beyond this tool. Manage DNS across every provider — in one dashboard.

Get started free →

SPF (Sender Policy Framework) is a DNS TXT record listing the mail servers allowed to send on behalf of your domain. Receiving servers check it to decide whether a message is legitimate — so a correct SPF record improves deliverability and protects your brand from spoofing.

This reads what your domain publishes and edits it, rather than building a record from nothing — because the most damaging SPF mistake is publishing a second one. Two records is not a stronger policy, it is no policy: receivers decline to pick between them and treat the domain as having none at all.

Every sender you add is costed against the ten DNS lookups a receiver will spend, while the record can still be changed. Going over that limit is a permanent error, and a record that names every one of your senders correctly then protects nothing.

InfraNest

Email security, done for you

InfraNest's email-security DNS template sets up SPF, DKIM and DMARC in one click, with a diff preview before anything is written.

  • SPF, DKIM & DMARC via built-in templates
  • Diff preview before you apply
  • Live sync to your DNS provider
  • Records validated as you go

Other providers

Frequently asked questions

#What is an SPF record?

SPF (Sender Policy Framework) is a DNS TXT record listing which servers are allowed to send email for your domain. Receiving servers check it against the connecting server and use the result to decide whether the message is genuine.

#Why does it ask for my domain?

So that it edits your record instead of inventing a new one. A blank form cannot know you already publish SPF, and publishing a second record leaves the domain with no usable policy at all. Reading it first also means the lookup cost shown is your real total, not the cost of the fragment being built. If you have no domain to check, there is a link to the plain builder under the domain box.

#Can I publish more than one SPF record?

No. A domain must have exactly one TXT record starting with v=spf1. Two of them is a permanent error, and receivers treat the domain as having no valid policy at all — so merge every sender into a single record.

#What is the 10-lookup limit?

Every include, a, mx, ptr, exists and redirect term costs a DNS lookup, and the spec caps the total at ten. Go over it and the record fails with a permerror. Three or four includes is usually fine; a dozen SaaS senders is not.

#Should I end with ~all or -all?

Start with ~all (softfail) while you confirm every legitimate sender is listed, then tighten to -all (hardfail) once your reports are clean. Never use +all — it authorises the entire internet to send as your domain.

#Where do I publish the record?

As a TXT record on the domain itself — the root, not a _spf subdomain. Subdomains do not inherit it, so a subdomain that sends mail needs its own record.

From the blog

More free tools

One lookup is a snapshot

InfraNest keeps checking — across every domain you own — and tells you when the answer changes instead of when a customer does.

Free plan · No credit card required · Set up in minutes