ActiScan

Free SPF Record Generator

Pick every service that sends email as your domain, and get a valid SPF TXT record to publish at your domain's root.

Sending sources

How to Use the Generator

1

Select your sending sources

Check every service that sends mail as your domain – Google Workspace, Microsoft 365, your CRM, and so on.

2

Add anything else

List any other IP ranges or mail servers not covered by the checkboxes, one per line.

3

Choose enforcement and generate

Pick -all, ~all, or ?all, then copy the record into a TXT record at your domain's root.

What Each Field Means

FieldWhat it doesExample
Sending sourcesOne checkbox per common provider. Each checked box adds that provider's include: mechanism to the record.Google Workspace → include:_spf.google.com
Other sending sourcesFree-text, one mechanism per line, for anything not in the checkbox list – another include:, or a raw IP range.ip4:203.0.113.5 or include:mail.example.com
EnforcementSets the trailing all mechanism, which controls what happens to mail from servers not listed above.-all (hard fail), ~all (soft fail), or ?all (neutral)

Example Outputs

Google Workspace only

v=spf1 include:_spf.google.com -all

Just the Google Workspace checkbox, enforcement set to -all.

Google Workspace + SendGrid

v=spf1 include:_spf.google.com include:sendgrid.net -all

Two checkboxes selected – one include: mechanism per provider, in the order they're listed.

Custom IP added

v=spf1 include:_spf.google.com ip4:203.0.113.5 -all

Google Workspace checked, plus a custom ip4: mechanism typed into the free-text field.

Next Steps

Verify what you just generated

After you publish the record, confirm it resolves correctly and is fully enforced.

SPF Checker →

Add DMARC on top of SPF

SPF alone doesn't stop spoofing – DMARC ties SPF and DKIM together with a policy and reporting.

DMARC Generator →

Managing multiple client domains?

ActiScan scans on a schedule and alerts you when a client's SPF record breaks or falls out of enforcement.

Start free →

Frequently Asked Questions

Is this SPF generator free?

Yes – build and download as many SPF records as you need, no signup required.

Where do I publish the record it gives me?

As a TXT record at your domain's root (often shown as @ in your DNS provider) – not a subdomain.

I already have an SPF record. What do I do with this one?

Replace it entirely. A domain can only have one SPF record – merge all your senders into a single v=spf1 line rather than publishing two.

Should I pick -all or ~all?

-all (hard fail) is the recommended, fully enforced setting. Pick ~all (soft fail) only temporarily, while you confirm every legitimate sender is listed, then switch to -all.

What if I select a lot of providers?

Each include: mechanism costs at least one DNS lookup, and SPF caps evaluation at 10 lookups total (RFC 7208). Stack enough providers and you can exceed it – check the result with the SPF checker after publishing to confirm it still resolves cleanly.

Generate and check SPF records as often as you need

Start free trial