InfraNestInfraNest

Google Workspace SPF record

The record Google Workspace needs, where it goes, and what to do if you send from more than one place.

TypeTXT
Host@
Valuev=spf1 include:_spf.google.com ~all
TTL3600
Open this in the tool

Publish it as a TXT record on the domain itself — the root, written as @ in most DNS panels. Not on a subdomain, and not on a _spf name.

One record only. A domain must have exactly one TXT record starting with v=spf1; a second is a permanent error, and receivers then treat the domain as having no policy at all. If you already publish SPF, add include:_spf.google.com to the record you have rather than publishing another.

Sending through more than one service? Each include costs a DNS lookup and the specification allows ten in total. Add every sender to the same record, and keep an eye on that count.

The ~all at the end is a soft fail: mail from anywhere else is treated as suspicious rather than refused. Once you are confident the list is complete, tighten it to -all.

After publishing, confirm it is live with a DNS lookup — a TXT record can take as long as its TTL to replace the old value.

Google Workspace’s own SPF documentation

Other providers

SPF Record Generator

Start in seconds

Bring your whole infrastructure into one modern dashboard.

Free plan · No credit card required · Set up in minutes