DNS Records (MX, SPF, DKIM, DMARC)

Understanding SPF (Sender Policy Framework) and How to Implement It

By the Domain India teamPublished 10 min read
Knowledge base article
Contents (12 sections)

SPF (Sender Policy Framework) is a DNS record that lists which servers may send email for your domain. Receiving mail servers check it to spot forged mail, and Gmail, Yahoo and Outlook.com now expect it before they trust your messages. This guide explains how SPF works, how to write a correct record, and where to add it on each kind of Domain India hosting.

Key takeaways

SPF is one TXT record at your domain's root, starting v=spf1, that lists every service allowed to send mail as your domain and ends with ~all or -all. Keep exactly one SPF record, stay under 10 DNS lookups, and add it wherever your domain's DNS is actually managed. On cPanel, Email › Email Deliverability checks SPF and shows the correct record for you. Pair SPF with DKIM and DMARC: SPF alone doesn't stop spoofing of the From address.

1. What SPF does, and what it doesn't

When a server receives a message, it looks at the envelope sender (the Return-Path address, also called MAIL FROM), looks up that domain's SPF record, and checks whether the connecting server's IP address is on the list. The result is pass, fail, softfail, neutral or none.

Two limits are worth knowing:

  • SPF checks the envelope sender, not the From address people see. A spammer can use their own envelope domain and still show your address in From. DMARC closes that gap by requiring SPF or DKIM to pass for the same domain that appears in From.
  • SPF breaks when mail is forwarded, because the forwarding server isn't on your list. DKIM usually survives forwarding, which is why you want both.

Since 2024, Gmail and Yahoo require every sender to have SPF or DKIM, and bulk senders to have SPF, DKIM and DMARC. Outlook.com applies similar rules to high-volume senders.

2. How to read an SPF record

A record is a single line of text:

text
v=spf1 a mx include:_spf.example-mailer.com ~all
PartMeaning
v=spf1Marks this TXT record as SPF. It must come first.
aThe IP addresses in your domain's A (and AAAA) records may send.
mxThe servers in your domain's MX records may send.
ip4:203.0.113.10This IPv4 address (or range, with /24 and so on) may send. ip6: does the same for IPv6.
include:domainAlso allow whatever that domain's SPF record allows. Used for mail services.
~allSoftfail everything else: accept but treat as suspicious.
-allFail everything else: receivers may reject it.

Each mechanism can take a qualifier: + pass (the default, so +a and a mean the same), - fail, ~ softfail and ? neutral. The ptr mechanism is deprecated; don't use it. The old separate "SPF" DNS record type is obsolete too: SPF is always published as TXT.

3. Write your record

  1. List every sender.
    Your hosting mail server, your business email service, your website's contact form, newsletter tools, CRM or billing software, and any app that sends mail "from" your domain.
  2. Get each service's SPF value.
    Mail services publish the include: to use in their setup guide. Don't guess it.
  3. Combine them into one line.
    Start with v=spf1, add each mechanism once, and end with one all.
  4. Choose the ending.
    Use ~all while you are still finding all your senders, and -all once DMARC reports show nothing legitimate failing.
  5. Check it
    with a lookup tool before and after you publish it (section 6).

Examples:

text
# Only your hosting server sends mail
v=spf1 a mx ~all

# Hosting server plus a newsletter service
v=spf1 a mx include:servers.newsletter-example.com ~all

# A fixed server IP plus an external mail provider
v=spf1 ip4:203.0.113.10 include:_spf.provider-example.com -all
Exactly one SPF record per domain

Two TXT records that both start with v=spf1 make SPF fail with a permanent error, and your mail may land in spam. The most common cause is adding a new service's record next to the existing one. Merge them into a single record instead.

4. The limits that break records quietly

  • 10 DNS lookups. Every include, a, mx, ptr, exists and redirect costs a lookup, and so do the includes inside those includes. Past 10, the result is a permanent error. Remove services you no longer use, and prefer ip4: for your own fixed servers, because ip4 and ip6 cost nothing.
  • 255 characters per string. A long record must be split into several quoted strings inside the same TXT record, which most DNS editors do for you. Never split it into two records.
  • Two "void" lookups. Includes that point at domains with no SPF record count against a small limit. Clean up stale includes.
  • Subdomains need their own record. SPF isn't inherited, so mail sent as news.example.com needs a record on news.example.com.
  • Domains that never send mail should publish v=spf1 -all so nobody can use them for spoofing.

5. Where to add SPF on Domain India hosting

SPF works only where your domain's DNS is actually served. If your domain uses our hosting nameservers, edit it in your control panel. If the DNS is elsewhere (another registrar, Cloudflare), add the record there. Not sure? See how to change your domain's DNS settings.

cPanel

Open Email › Email Deliverability. It lists each domain, says whether SPF and DKIM are valid, and shows the exact record to publish. If the domain uses our hosting nameservers, it can install the record for you; otherwise, copy it to your DNS provider. To add a third-party service, edit the existing record in Domains › Zone Editor rather than adding a new one. DKIM is on by default for new cPanel accounts, so a correct SPF record plus the existing DKIM key covers most mail. Details: how to make DNS changes in cPanel.

DirectAdmin and Webuzo

Open the DNS management page for the domain and look for an existing TXT record starting v=spf1 before you add anything. If there is one, edit it to include your new sender; if there is none, add one TXT record at the domain's root. On DirectAdmin, DKIM uses the selector x; see how to check and manage DKIM in DirectAdmin.

DirectAdmin DNS Management page for example.com listing A, NS, MX and TXT records, with Add Record and Override TTL Value buttons
An existing v=spf1 TXT record in DirectAdmin's DNS Management.
Webuzo Advance DNS Settings page listing the zone records for example.com, including SPF and DMARC TXT records, with Add Record
Webuzo's DNS zone page, with the domain's v=spf1 TXT record.

Windows (Plesk)

When the domain uses our hosting nameservers, Plesk creates SPF, DKIM and DMARC records for mail-enabled domains. Edit the existing SPF record in Plesk's DNS settings to add a service; don't add a second record or replace a strict -all with a weaker one.

Business Email

Business Email signs every message with DKIM and provides the SPF and DMARC records to publish for your domain. If you also send from your hosting account or a newsletter tool, merge everything into one SPF record.

6. Test and troubleshoot

After publishing, allow time for DNS caches to update, then check:

  • Lookup tools: MXToolbox's SPF check or Google Admin Toolbox's Check MX show the record, the lookup count and any syntax errors.
  • Command line: dig +short TXT example.com (or nslookup -type=TXT example.com) shows what the world sees.
  • Real mail: send a message to a Gmail address and choose Show original. The top shows SPF, DKIM and DMARC with PASS or FAIL. The full method is in how to test email deliverability.
ResultLikely causeFix
permerrorTwo SPF records, a syntax error or more than 10 lookupsMerge into one record, fix the syntax, remove unused includes
softfail or failThe sending service isn't in your recordAdd that service's include or IP
noneNo SPF record found where the DNS is servedPublish it at the DNS provider your nameservers point to
fail on forwarded mail onlyForwarding sends from another serverMake sure DKIM passes; DMARC accepts either

On our cPanel servers, SRS (which rewrites forwarded mail so SPF keeps working) is off, so mail forwarded from a cPanel mailbox to an outside address relies on DKIM.

7. SPF, DKIM and DMARC together

SPF says which servers may send. DKIM signs each message so receivers can prove it wasn't altered and that your domain sent it. DMARC ties both to the visible From address, tells receivers what to do with failures and sends you reports. Set up SPF and DKIM first, then add DMARC with p=none, read the reports, and tighten gradually. See setting up DMARC and the wider email deliverability guide.

8. Where Domain India fits

Every Domain India shared hosting plan includes mailboxes on your domain and DNS editing for domains on our hosting nameservers, so you can publish SPF yourself. Shared hosting isn't for bulk mail: outgoing mail is limited to 200 messages per hour per account on cPanel and 1,000 per day on DirectAdmin. For mail kept separate from your website hosting, Business Email is priced per mailbox:

Business Email
₹60/mo + GST
  • Priced per mailbox - start with one
  • Email at your own domain ([email protected])
  • Add and remove mailboxes yourself
  • Webmail with calendar, contacts and tasks
See plan details

The price on the card is a live Domain India list price and excludes 18% GST.

What is an SPF record?

An SPF record is a DNS TXT record at your domain, starting v=spf1, that lists the servers allowed to send email for that domain. Receiving servers compare the sending server's IP address with the list and mark the message pass or fail.

Can a domain have two SPF records?

No. Two TXT records starting v=spf1 cause a permanent SPF error. Merge every sender into one record.

Should I use ~all or -all?

Use ~all (softfail) while you are still confirming every service that sends mail for you, and move to -all (fail) once your DMARC reports show that all legitimate mail passes.

What is the SPF 10-lookup limit?

SPF evaluation may make at most 10 DNS lookups. Each include, a, mx, exists and redirect counts, including those nested inside includes. Beyond 10 the record returns a permanent error, so remove unused includes and use ip4 or ip6 for fixed servers.

Where do I add the SPF record for my domain?

Add it wherever your domain's DNS is managed. If the domain uses Domain India hosting nameservers, use your control panel (on cPanel, Email Deliverability or the Zone Editor). If the DNS is hosted elsewhere, add it at that provider.

Does SPF stop people spoofing my From address?

Not on its own, because SPF checks the envelope sender, not the visible From address. DMARC, combined with SPF and DKIM, is what protects the From address.

Why does SPF fail on forwarded mail?

A forwarding server resends the message from its own IP address, which isn't in your SPF record. DKIM signatures usually survive forwarding, so DMARC can still pass on DKIM.

Ready to set it up? Check your record in cPanel's Email Deliverability or your DNS provider, then follow setting up DMARC. If a result still fails, open a support ticket with the domain name and the message headers.

Want a second pair of eyes on your SPF record?

Send us your domain and where its DNS is managed, and support will check your SPF, DKIM and DMARC records with you.

Open a ticket

Ready when you are

Get Business Email from ₹60/mo + GST

See plans

Was this article helpful?

Your answer helps us decide what to improve next.

Still need help? Open a support ticket and our team will reply.

Prefer an app? Add this site to your home screen.Get the app