What it is
When a server receives a message, it looks at the domain the message claims to be sent from and fetches that domain's SPF record. If the sending server is on the list, SPF passes. If it is not, the ending of the record says what to do.
Reading a record
v=spf1 include:spf.protection.outlook.com include:_spf.yournewsletter.example -all
| Part | What it says |
|---|---|
| v=spf1 | This is an SPF record. |
| include: | Trust the servers this other domain lists. One for each service that sends for you. |
| ip4: ip6: | Trust this address. |
| -all | Refuse everyone else. This is the ending you want. |
| ~all | Be suspicious of everyone else, but accept them. |
| ?all +all | No opinion, or accept anyone. Both make the record useless. |
The ten-lookup limit
Reading an SPF record is allowed to cost ten DNS lookups and no more. Every include costs at least one, and the services you include have includes of their own. Go past ten and the receiving server stops reading: the result is an error, and your real email fails SPF. Nothing warns you. In our scan of 200 English housing associations, 10% had gone over.
Source: OuterMark, UK Housing Email Security Report 2026.
What goes wrong
Two records
A domain may publish one SPF record. Two cancel each other out.
A soft ending
~all asks receivers to be suspicious. It does not ask them to refuse.
Too many lookups
See above.
A supplier you left
An include that points at a lapsed domain can be registered by a stranger, who then sends as you with your blessing.
What SPF cannot do
SPF checks the hidden return address, not the From line your customers read. It also breaks when a message is forwarded. That is why SPF alone does not stop impersonation, and why DMARC and DKIM exist.
How OuterMark handles it
The free check reads your record, counts its lookups and checks each include still answers (checks 1, 2 and 11 on /scanner). On Managed DMARC, Managed SPF replaces your record with one we host: we flatten it to the addresses behind your includes and re-flatten it as your senders change, so it stays under the limit. A domain whose record we cannot take over safely is refused, with the reason, and left exactly as it was.
Questions
Does flattening mean you control who sends for me?
No. The list is still yours. We keep it short enough to work.
We added a new service and its email is failing. Why?
It is probably not in your SPF record yet, or adding it took you past ten lookups.
Is -all safe?
Yes, once every real sender is on the list. Finding them is what DMARC reports are for.