Free tool

SPF record generator

An SPF record is one TXT record at your domain's root that lists every service allowed to send as the domain, such as v=spf1 include:_spf.google.com ~all for Google Workspace.

Your domain

Optional. Read the record it has now, and the new one keeps everything already in it.

Where you send email from

Values from each provider's own setup guide. Some services carry SPF on their own return-path and need nothing here.

Mailboxes

Sending services

Marketing and CRM

Sources: each provider's own setup guide

Your own servers and other services

IP addresses or ranges of servers that send as the domain, and include values from services not in the list.

Mail from servers not listed

Ending
Your SPF record

v=spf1 ~all

DNS lookups0 of 10
  • Type
    TXT
    Name
    @
    TTL
    3600

    Value: the record above

    @ means the domain itself

  • NotePick the services that send email as your domain, or read the domain's current record.
Where to enter it at your DNS host
  • Cloudflare: Type TXT, Name @, Content the value, TTL Auto
  • GoDaddy: Add New Record, Type TXT, Name @, Value the value, TTL 1 hour
  • Namecheap: Advanced DNS, Add New Record, TXT Record, Host @, Value the value
  • Route 53: Create record, Record name left blank, Type TXT, value in double quotes; split values over 255 characters into quoted parts
  • Google Cloud DNS, Squarespace and others: Host @, or the full name @ where the panel asks for it; one TXT record with the value
  • Changes show up within the TTL, usually minutes; some hosts take up to an hour to publish.

Send the record to your DNS admin

We email the record, its name and TTL, and the findings above, so whoever manages DNS can paste it as is.

Setting up domains for cold email?

Outreach2day buys the domains, sets SPF, DKIM and DMARC on each one and creates warmed-up mailboxes: $2.50 a mailbox a month, 12 minimum. From 1,000 mailboxes we quote a volume price on a call.

About this tool

About the SPF record generator

Pick the services you send from above and the generator builds the record, counts its DNS lookups against the limit of 10 and shows the name and TTL to enter at your DNS host.

Already have a record? Enter the domain and read it first. A domain can publish only one SPF record, so the new one keeps everything already in it. Every include comes from the provider's own setup guide, linked under the generator.

How it works

How the record is built

  • One record per domain: v=spf1, the servers and services allowed to send, then the ending; a second SPF record makes SPF fail for both
  • include: pulls in another domain's SPF record, which is how services publish their servers; each include costs at least one DNS lookup, more when it nests others
  • ip4: and ip6: list your own servers and cost no lookups
  • a and mx allow the domain's own web or mail servers; each costs a lookup, so list the IPs when you know them
  • ~all (soft fail) marks mail from unlisted servers as suspicious and -all (fail) asks receivers to reject it; ~all is the common choice while you are still finding every sender, and DMARC decides what happens to the mail either way
  • Name: @ (the domain itself) in most DNS panels; TTL 3600, or 300 before a change you may need to roll back
  • A domain that sends no email publishes v=spf1 -all, with a DMARC record at p=reject, so nobody can send as it

Background

The 10 DNS lookup limit

RFC 7208 caps an SPF check at 10 DNS lookups. Every include, a, mx, ptr, exists and redirect counts, including the ones inside the records you include. Above 10 the check returns permerror, SPF fails for every message, and DMARC passes only where DKIM is aligned.

The meter in the generator walks the real include tree in DNS as you pick services. On 9 October 2026 Mailgun's include cost 5 lookups, Zoho Mail's 2, SendGrid's 2, and Google Workspace's and Microsoft 365's 1 each.

Over the limit, remove the services you no longer send from first. If every one is still needed, the SPF flattening tool replaces the heaviest includes with the addresses they resolve to.

Background

Which services need an include

Several sending services put SPF on their own return-path domain, so adding their include to your root record costs lookups and changes nothing. The generator marks these as "No SPF change"; DKIM and DMARC still need their records.

  • Google Workspace: include:_spf.google.com; Microsoft 365: include:spf.protection.outlook.com (GCC High and 21Vianet have their own)
  • Zoho Mail: include:zohomail.com, or include:one.zoho.com when other Zoho apps send as the domain
  • Mailgun: include:mailgun.org on the domain you added to Mailgun, which Mailgun recommends be a subdomain
  • SendGrid: nothing with automated security on (its CNAMEs carry SPF), include:sendgrid.net with it off
  • Amazon SES: nothing with the default MAIL FROM domain; with a custom one, an MX and a TXT record on the MAIL FROM subdomain for your AWS Region
  • HubSpot: an include that is different for every account, copied from HubSpot's domain settings
  • Brevo: include:spf.brevo.com only with a dedicated IP; Postmark, Mailchimp and Mandrill: no change to your SPF record
  • Google Workspace step by step, DKIM and DMARC included: Google Workspace SPF, DKIM and DMARC setup

Background

After you publish it

Delete the old SPF record in the same edit; two records fail. Then check the live record: the SPF, DKIM and DMARC checker reads it from DNS, counts the lookups again and checks DKIM and DMARC next to it.

The SPF checker shows the full include tree of the live record.

SPF covers the envelope sender. For Gmail, Yahoo and Outlook the domain also needs DKIM and a DMARC record (what cold email domains need); build the DMARC record with the DMARC record generator.

Free guide19 min read

Send 100,000 cold emails a month

Domains and mailboxes you need, DNS, warm-up, lists, copy and follow-ups, with a launch checklist, sent to your inbox.

Unsubscribe in one click.

Questions

How do I create an SPF record?

List every service that sends email as your domain, put their include values and your own server IPs into one record that starts with v=spf1 and ends with ~all or -all, and publish it as a TXT record at the domain's root (@). The generator above builds it and counts the DNS lookups.

Can a domain have two SPF records?

No. With two v=spf1 records receivers return permerror and SPF fails for every message. Merge both into one record: read the current record above and add the new service to it.

How do I add Google Workspace or Microsoft 365 to an existing SPF record?

Add include:_spf.google.com or include:spf.protection.outlook.com before the all term of the record you have, in the same record. Enter your domain above and tick the provider; the generator keeps what is already there.

What is the difference between ~all and -all?

~all is a soft fail: receivers treat mail from unlisted servers as suspicious, usually the spam folder. -all is a fail: receivers may reject it. With DMARC published, receivers follow the DMARC policy, so ~all is enough for most domains.

Where do I put the SPF record?

As a TXT record at the domain itself: Name @ in Cloudflare, GoDaddy and Namecheap, a blank name in Route 53. TTL 3600 works. A subdomain that sends mail gets its own record at that subdomain.

What happens with more than 10 DNS lookups?

SPF returns permerror and fails for every message, including mail from the services you listed. Remove includes you no longer use, or flatten the heaviest with the SPF flattening tool.

In your AI assistant

Run the same checks in Claude or ChatGPT

Free SKILL.md files with the rules behind this tool. Install them in Claude or Claude Code, or paste them into ChatGPT, Gemini, Grok or Cursor.

Mailboxes, warm-up and sending in one place

$2.50 a mailbox a month. DNS records are set for you, and every mailbox shows its warm-up numbers from day one.

Deliverability call

Talk to our deliverability team

Book a call with the people who run our mailbox infrastructure. We look at your current setup and tell you what to change. Running 1,000+ mailboxes? We also quote a volume price below every vendor list price in our comparisons, warm-up and sending included.

  • Review your domains, DNS records and current inbox placement
  • Size the setup: domains, mailboxes per domain and daily volume per mailbox
  • Plan warm-up and the move from your current provider or sequencer
  • 1,000+ mailboxes: a volume price per mailbox for your setup

Free call

See open times in your time zone and book on this page.

Or open the booking page