Authentication
Updated
SPF (Sender Policy Framework)
Definition
SPF (Sender Policy Framework) is a DNS TXT record that lists which servers may send email using a domain in the envelope sender (Return-Path). Receivers compare the connecting server's IP against that list and record pass, fail, softfail or neutral.
How it works
SPF is defined in RFC 7208. When a server receives a message, it reads the domain in the SMTP MAIL FROM command (the envelope sender, which ends up in the Return-Path header) and looks up the TXT record starting with v=spf1 on that domain.
The record is read left to right. Mechanisms such as ip4, ip6, a, mx and include either match the connecting IP or move on. The first match decides the result, and the final all mechanism sets what happens to everything else: -all means fail, ~all means softfail, ?all means neutral.
SPF does not check the visible From address. A message can pass SPF for a bounce domain like ses.example.com while showing From: [email protected]. That gap is why DMARC adds alignment: the SPF-authenticated domain must match the From domain.
Example
Google Workspace and Amazon SES may send for example.com. Anything else gets a softfail.
Why it matters
Since February 2024, Gmail and Yahoo require every sender to authenticate with SPF or DKIM, and bulk senders (around 5,000+ messages a day to Gmail) to have both, plus DMARC. Unauthenticated mail is rate limited or rejected.
SPF is also one of the two ways a message can pass DMARC. Without an aligned SPF pass, DMARC depends entirely on DKIM.
Best practices
- Publish exactly one v=spf1 record per hostname. Two SPF records is a permanent error, and receivers treat it like no SPF at all.
- Stay under 10 DNS lookups. include, a, mx, ptr, exists and redirect each count, including nested includes. Going over returns permerror.
- Start with ~all while you inventory senders, then move to -all once every legitimate source is listed. DMARC enforcement matters more than the SPF qualifier.
- Remove includes for tools you no longer use. Each one widens who can pass SPF for your domain.
- Remember that forwarding breaks SPF, because the forwarder's IP is not in your record. DKIM survives forwarding, so never rely on SPF alone.
How Lumail handles SPF
Lumail sends through Amazon SES with a custom MAIL FROM domain, ses.your-domain.com. You add an SPF TXT record (v=spf1 include:amazonses.com ~all) and an MX record on that subdomain, so SPF passes and aligns with your From domain under DMARC's relaxed alignment.
Lumail checks these records when you add a domain during onboarding and on the domain page. Sending to your audience unlocks automatically once the records verify.
Check a real message with the free mail tester or the spam tester.
Frequently asked questions
What is the SPF 10 DNS lookup limit?
RFC 7208 caps SPF evaluation at 10 mechanisms that need a DNS query (include, a, mx, ptr, exists and the redirect modifier), counting nested includes. Exceeding it returns a permanent error, so the record fails to authenticate anything.
Should I use ~all or -all?
Both are valid. ~all (softfail) is the safer default while you confirm every sender. -all (fail) is stricter. Under DMARC, the DMARC policy decides what happens to failing mail, so p=quarantine or p=reject protects you more than the SPF qualifier does.
Can a domain have two SPF records?
No. More than one v=spf1 record on the same hostname is a permerror. Merge all senders into a single record with multiple include mechanisms.
Does SPF protect the From address people see?
Not by itself. SPF checks the envelope sender (Return-Path). DMARC is what ties the SPF result to the visible From domain through alignment.
Related terms, tools and docs
- AuthenticationDKIMDKIM (DomainKeys Identified Mail) is a cryptographic signature added to each email's headers.
- AuthenticationDMARCDMARC is a DNS TXT record at _dmarc.yourdomain.com that tells receivers what to do with mail that claims to be from your domain but fails authentication.
- DeliverabilityMX recordAn MX (Mail Exchanger) record is a DNS record that names the servers that accept incoming email for a domain, each with a priority number.
- DeliverabilityEmail deliverabilityEmail deliverability is the ability of your emails to reach recipients' inboxes rather than bouncing or landing in spam.
- Free toolSPF checkerLook up a domain's SPF record and count its DNS lookups.
- Free toolFree mail testerSend a real email and get an SPF, DKIM, DMARC and content report.
- Free toolDMARC checkerRead a domain's DMARC policy, alignment and reporting tags.
- DocsHow to fix MAIL FROMMX and SPF records on ses.your-domain.com.
- DocsHow to verify a sending domainEvery DNS record Lumail asks for, in order.
- DocsEmail domainsSend from your own domain instead of a shared one.
Browse every definition in the email marketing glossary.
Send your next email with Lumail.
3,000 emails a month free. Unlimited subscribers on every plan. Campaigns, automations and transactional email on one domain.