technical · sourced answer

SPF Sender Policy Framework Explained

Sender Policy Framework (SPF) is a DNS based email authentication mechanism that allows a domain owner to specify which mail servers are authorized to send emails on behalf of their domain. It prevents spoofing by allowing receiving mail servers to verify that the sending IP address is listed in the domain's SPF record.

How SPF Works Mechanically

When an email is received, the receiving server looks up the TXT record of the domain found in the SMTP MAIL FROM address. The SPF record contains a list of authorized IP addresses or third party services. The receiver compares the IP address of the connecting SMTP server against this list. If the IP is present, the check passes. If it is not, the result is a fail or softfail depending on the record qualifier used.

Importance for Senders

SPF is a primary defense against email spoofing and phishing. Without a valid SPF record, receiving servers have no way to verify if an email claiming to be from your domain is legitimate. This often leads to emails being flagged as spam or rejected entirely. Implementing SPF is a prerequisite for DMARC alignment, which provides a more robust framework for reporting and enforcement of email security policies.

Common Operational Mistakes

A frequent error is exceeding the 10 DNS lookup limit. SPF records that use too many include mechanisms trigger a PermError, causing the authentication to fail. Another common mistake is having multiple SPF records on a single domain, which is invalid and results in an automatic fail. Senders should merge all authorized sources into one single TXT record to ensure consistent evaluation.

SPF Record Example

A typical SPF record looks like v=spf1 ip4:1.2.3.4 include:_spf.google.com ~all. In this example, v=spf1 identifies the version, ip4:1.2.3.4 authorizes a specific server, include:_spf.google.com authorizes Google Workspace, and ~all indicates a softfail for any other source. You can verify your current record using SendHQ free tools at https://sendhq.cc/tools to ensure syntax is correct.

Evaluation Qualifiers

The record ends with a qualifier that tells the receiver how to handle unauthorized mail. The minus sign -all indicates a hard fail, suggesting the mail should be rejected. The tilde ~all indicates a softfail, suggesting the mail be accepted but marked as suspicious. The question mark ?all is a neutral result, providing no specific instruction to the receiving server.

Questions teams ask

Can I have more than one SPF record?

No. A domain must have exactly one SPF record. Multiple records will cause a permanent error and result in authentication failure.

What is the DNS lookup limit?

SPF records are limited to 10 recursive DNS lookups. Exceeding this limit causes a PermError, making the record invalid.

Does SPF prevent all spoofing?

SPF only validates the Return-Path address, not the From header seen by the user. DKIM and DMARC are required for full header validation.

Primary sources