Free tool

SPF record generator

Pick every service that sends email for your domain and get one valid SPF TXT record — with a running count of the DNS lookups SPF allows.

Who sends email for you?

Your SPF TXT record

v=spf1 include:_spf.google.com include:amazonses.com ~all

Estimated DNS lookups: 5 / 10

Deliverability, handled

Oitomail verifies SPF, DKIM and DMARC in a guided wizard, warms your domain automatically and blocks sends that would damage your reputation.

Start 7-day trial

How to publish your SPF record

  1. Open your DNS provider and create a TXT record on the root of your sending domain.
  2. Leave the host/name as @ (or your subdomain, e.g. mail) and paste the value below.
  3. Delete any other v=spf1 TXT record — only one may exist per domain.
  4. Wait for propagation, then send a test message and check the Authentication-Results header for spf=pass.

Frequently asked questions

What is an SPF record?

SPF (Sender Policy Framework) is a DNS TXT record that lists which servers are allowed to send email for your domain. Receiving servers check it to decide whether a message is forged.

Can I have two SPF records?

No. A domain must publish exactly one SPF TXT record. If you use several providers, merge all of their include: mechanisms into a single record.

What is the 10 lookup limit?

SPF evaluation allows a maximum of 10 DNS lookups. Every include, a, mx, ptr and exists mechanism counts. Exceeding it makes the record permerror and SPF fails.

Should I use -all or ~all?

Use ~all (softfail) while you confirm every legitimate sender is listed, then tighten to -all (hardfail) for the strongest protection against spoofing.

Turn activity into retained revenue.

Start a 7-day trial with the full platform — no credit card. Or talk to us about a Platinum or Enterprise rollout.