Last updated: July 2026 — includes the Gmail/Yahoo sender requirements in force since 2024
SPF (Sender Policy Framework) is a DNS record listing which servers may send email for your domain. Receiving servers check it on every message; without it, your mail leans toward spam — and since 2024, Gmail and Yahoo require SPF or DKIM to accept mail at all, with bulk senders needing both plus DMARC.
The record, decoded
SPF is one TXT record on your root domain:
v=spf1 include:_spf.google.com ~all
v=spf1— always first.- Mechanisms list allowed senders:
include:(another provider’s SPF),ip4:/ip6:(a server address),a(your domain’s A record),mx(your MX hosts). - The
allqualifier ends the record and sets the policy for everyone else:~all= softfail (mark suspicious),-all= hardfail (reject). Start with~all; move to-allonce you’re sure the list is complete.
Real-world examples
# Google Workspace only
v=spf1 include:_spf.google.com ~all
# Website on your own VPS sends via PHP, newsletters via Brevo
v=spf1 ip4:203.0.113.25 include:spf.brevo.com ~all
# Microsoft 365
v=spf1 include:spf.protection.outlook.com ~all
Add it in your DNS panel as: Type TXT, Host @, Value as above. One SPF record per domain — two records is an automatic permerror; merge the mechanisms into one line instead.
Verify it
dig +short TXT yourdomain.com | grep spf1
Then send a message to a Gmail address, open it → three-dot menu → Show original — you want SPF: PASS (and ideally DKIM/DMARC: PASS on the same screen).
The 10-lookup limit
SPF allows at most 10 DNS lookups per check; include:, a and mx each cost one, recursively. Stack enough services (Google + Mailchimp + helpdesk + CRM…) and you exceed it — result: permerror, treated as no SPF at all. Audit with any online SPF checker; the fix is removing services that no longer send for you or using a flattening service.
SPF alone is not enough anymore
SPF validates the envelope sender and breaks on forwarded mail. Modern deliverability is the trio:
- SPF — the record above.
- DKIM — cryptographic signature; enable in your mail provider and publish the key they give you.
- DMARC — the policy tying them together:
v=DMARC1; p=quarantine; rua=mailto:dmarc@yourdomain.comon_dmarc.yourdomain.com.
Set up all three and watch the DMARC reports for a couple of weeks before tightening policies. If messages still bounce afterward, decode the exact server response with my SMTP error codes reference.

One thought on “SPF Records for Outgoing Mail: Setup That Actually Delivers”
Comments are closed.