Free SPF Record Generator
Pick every service that sends email as your domain, and get a valid SPF TXT record to publish at your domain's root.
How to Use the Generator
Select your sending sources
Check every service that sends mail as your domain – Google Workspace, Microsoft 365, your CRM, and so on.
Add anything else
List any other IP ranges or mail servers not covered by the checkboxes, one per line.
Choose enforcement and generate
Pick -all, ~all, or ?all, then copy the record into a TXT record at your domain's root.
What Each Field Means
| Field | What it does | Example |
|---|---|---|
| Sending sources | One checkbox per common provider. Each checked box adds that provider's include: mechanism to the record. | Google Workspace → include:_spf.google.com |
| Other sending sources | Free-text, one mechanism per line, for anything not in the checkbox list – another include:, or a raw IP range. | ip4:203.0.113.5 or include:mail.example.com |
| Enforcement | Sets the trailing all mechanism, which controls what happens to mail from servers not listed above. | -all (hard fail), ~all (soft fail), or ?all (neutral) |
Example Outputs
Google Workspace only
v=spf1 include:_spf.google.com -all
Just the Google Workspace checkbox, enforcement set to -all.
Google Workspace + SendGrid
v=spf1 include:_spf.google.com include:sendgrid.net -all
Two checkboxes selected – one include: mechanism per provider, in the order they're listed.
Custom IP added
v=spf1 include:_spf.google.com ip4:203.0.113.5 -all
Google Workspace checked, plus a custom ip4: mechanism typed into the free-text field.
Next Steps
Verify what you just generated
After you publish the record, confirm it resolves correctly and is fully enforced.
SPF Checker →Add DMARC on top of SPF
SPF alone doesn't stop spoofing – DMARC ties SPF and DKIM together with a policy and reporting.
DMARC Generator →Managing multiple client domains?
ActiScan scans on a schedule and alerts you when a client's SPF record breaks or falls out of enforcement.
Start free →Frequently Asked Questions
Is this SPF generator free?
Yes – build and download as many SPF records as you need, no signup required.
Where do I publish the record it gives me?
As a TXT record at your domain's root (often shown as @ in your DNS provider) – not a subdomain.
I already have an SPF record. What do I do with this one?
Replace it entirely. A domain can only have one SPF record – merge all your senders into a single v=spf1 line rather than publishing two.
Should I pick -all or ~all?
-all (hard fail) is the recommended, fully enforced setting. Pick ~all (soft fail) only temporarily, while you confirm every legitimate sender is listed, then switch to -all.
What if I select a lot of providers?
Each include: mechanism costs at least one DNS lookup, and SPF caps evaluation at 10 lookups total (RFC 7208). Stack enough providers and you can exceed it – check the result with the SPF checker after publishing to confirm it still resolves cleanly.