SPF

The list of who may send as you.

SPF is a DNS record that lists the services allowed to send email for your domain. It is the oldest of the three email checks and the easiest to break without noticing.

Last reviewed 27 September 2026

What it is

When a server receives a message, it looks at the domain the message claims to be sent from and fetches that domain's SPF record. If the sending server is on the list, SPF passes. If it is not, the ending of the record says what to do.

Reading a record

DNS · TXT · yourcompany.co.ukExample
v=spf1 include:spf.protection.outlook.com include:_spf.yournewsletter.example -all
Reading a record
PartWhat it says
v=spf1This is an SPF record.
include:Trust the servers this other domain lists. One for each service that sends for you.
ip4: ip6:Trust this address.
-allRefuse everyone else. This is the ending you want.
~allBe suspicious of everyone else, but accept them.
?all +allNo opinion, or accept anyone. Both make the record useless.

The ten-lookup limit

Reading an SPF record is allowed to cost ten DNS lookups and no more. Every include costs at least one, and the services you include have includes of their own. Go past ten and the receiving server stops reading: the result is an error, and your real email fails SPF. Nothing warns you. In our scan of 200 English housing associations, 10% had gone over.

Source: OuterMark, UK Housing Email Security Report 2026.

What goes wrong

Two records

A domain may publish one SPF record. Two cancel each other out.

A soft ending

~all asks receivers to be suspicious. It does not ask them to refuse.

Too many lookups

See above.

A supplier you left

An include that points at a lapsed domain can be registered by a stranger, who then sends as you with your blessing.

What SPF cannot do

SPF checks the hidden return address, not the From line your customers read. It also breaks when a message is forwarded. That is why SPF alone does not stop impersonation, and why DMARC and DKIM exist.

How OuterMark handles it

The free check reads your record, counts its lookups and checks each include still answers (checks 1, 2 and 11 on /scanner). On Managed DMARC, Managed SPF replaces your record with one we host: we flatten it to the addresses behind your includes and re-flatten it as your senders change, so it stays under the limit. A domain whose record we cannot take over safely is refused, with the reason, and left exactly as it was.

Questions

Does flattening mean you control who sends for me?

No. The list is still yours. We keep it short enough to work.

We added a new service and its email is failing. Why?

It is probably not in your SPF record yet, or adding it took you past ten lookups.

Is -all safe?

Yes, once every real sender is on the list. Finding them is what DMARC reports are for.

See where your domain stands.

The free check reads these records in about 30 seconds.