Email / DNS

SPF Record Generator

Build an SPF record for your domain by ticking the services that send your email, such as Google Workspace, Microsoft 365, or Mailchimp, with a count of DNS lookups against the limit of 10.

SPF Record Generator: SPF lists the servers allowed to send email for a domain, as RFC 7208 defines. Each include, a, and mx mechanism costs a DNS lookup when a receiver checks the record, and so do the includes inside a provider's own record; more than 10 lookups and the check fails. The generator counts them, using each provider's record as measured on 2 October 2026, and splits records over 255 characters into the separate strings a TXT record needs. Runs 100% locally in your browser with zero server file uploads.

Category
Web tools
Runs
In your browser
Cost
Free · no sign-up
Availability
Ready to use
SPF record generatorLocal processing

Runs entirely in your browser

Services that send email for your domain
SPFHost / name: @Type: TXT
v=spf1 include:_spf.google.com ~all

DNS lookups: 1 of 10

Publish one SPF record per domain, as a TXT record on the domain itself; two SPF records make both invalid. The lookups inside each provider's include were measured on 2 October 2026 and can change; check your provider's current instructions.

SPF, DKIM, and DMARC

SPF checks the server that sent a message; DKIM checks a signature added by the sender; DMARC ties both to the address in the From line and tells receivers what to do when they fail. All three are needed for reliable delivery to Gmail, Outlook, and Yahoo.

Next, publish a policy with the DMARC record generator, and check the records are live with DNS lookup.

Changing records safely

Lower the TXT record's TTL a day before a change, edit the existing SPF record rather than adding a second, and send test messages to an address that shows authentication results, such as a Gmail account's Show original view.

How to use it

  1. Tick each service that sends email as your domain, and add your own servers' addresses.
  2. Choose what happens to mail from anywhere else: soft fail or fail.
  3. Copy the record into a TXT record on your domain, replacing any SPF record already there.

Privacy & limitations

The record is built in your browser; no DNS queries are made.

Related tools

Frequently asked questions

Should I use ~all or -all?

~all (soft fail) asks receivers to accept but mark failing mail, a safe start; -all (fail) asks them to reject it. With DMARC in place, many domains use ~all and let DMARC decide.

Can I have two SPF records?

No: a domain must publish only one; two make SPF fail. Merge them into one record with all the includes.

What if I go over 10 lookups?

Remove services you no longer use, replace includes with the provider's IP ranges where they publish them, or send some mail from a subdomain with its own record.

Free tool · runs in your browser · no account required