SPF Records for Outgoing Mail: Setup That Actually Delivers

Create a correct SPF record for outgoing mail – syntax explained, examples for Google Workspace and your own server, the 10-lookup limit, plus DKIM/DMARC.

SPF Records for Outgoing Emails

Last updated: July 2026 — includes the Gmail/Yahoo sender requirements in force since 2024

SPF (Sender Policy Framework) is a DNS record listing which servers may send email for your domain. Receiving servers check it on every message; without it, your mail leans toward spam — and since 2024, Gmail and Yahoo require SPF or DKIM to accept mail at all, with bulk senders needing both plus DMARC.

The record, decoded

SPF is one TXT record on your root domain:

v=spf1 include:_spf.google.com ~all
  • v=spf1 — always first.
  • Mechanisms list allowed senders: include: (another provider’s SPF), ip4:/ip6: (a server address), a (your domain’s A record), mx (your MX hosts).
  • The all qualifier ends the record and sets the policy for everyone else: ~all = softfail (mark suspicious), -all = hardfail (reject). Start with ~all; move to -all once you’re sure the list is complete.

Real-world examples

# Google Workspace only
v=spf1 include:_spf.google.com ~all

# Website on your own VPS sends via PHP, newsletters via Brevo
v=spf1 ip4:203.0.113.25 include:spf.brevo.com ~all

# Microsoft 365
v=spf1 include:spf.protection.outlook.com ~all

Add it in your DNS panel as: Type TXT, Host @, Value as above. One SPF record per domain — two records is an automatic permerror; merge the mechanisms into one line instead.

Verify it

dig +short TXT yourdomain.com | grep spf1

Then send a message to a Gmail address, open it → three-dot menu → Show original — you want SPF: PASS (and ideally DKIM/DMARC: PASS on the same screen).

The 10-lookup limit

SPF allows at most 10 DNS lookups per check; include:, a and mx each cost one, recursively. Stack enough services (Google + Mailchimp + helpdesk + CRM…) and you exceed it — result: permerror, treated as no SPF at all. Audit with any online SPF checker; the fix is removing services that no longer send for you or using a flattening service.

SPF alone is not enough anymore

SPF validates the envelope sender and breaks on forwarded mail. Modern deliverability is the trio:

  1. SPF — the record above.
  2. DKIM — cryptographic signature; enable in your mail provider and publish the key they give you.
  3. DMARC — the policy tying them together: v=DMARC1; p=quarantine; rua=mailto:dmarc@yourdomain.com on _dmarc.yourdomain.com.

Set up all three and watch the DMARC reports for a couple of weeks before tightening policies. If messages still bounce afterward, decode the exact server response with my SMTP error codes reference.

Comments

comments

One thought on “SPF Records for Outgoing Mail: Setup That Actually Delivers”

Comments are closed.