SPF Record Generator
Build one SPF record that keeps your existing senders, count every DNS lookup, test a sending IP and get safely under the 10-lookup limit.
The SPF record generator reads the SPF record your domain publishes now, adds the services you choose and shows the single record to publish. Every check follows RFC 7208, the standard receiving servers use to read SPF.
What SPF Checks
SPF checks the envelope sender, also called the return-path, not the From address people see. That is why some services need an include on your domain and others do not: Postmark, Mailchimp and SendGrid with automated security send with their own return-path, so SPF is checked against their domain. Adding their include to yours only spends lookups.
Generate A Record
Enter your domain and press Look Up. The tool reads your current record and your MX records.
Pick the services that send for you. A selected chip shows the lookups it adds, measured live.
Add your own servers under Your Own Servers And Other Includes: IPv4 and IPv6 addresses or ranges, other includes, and the a or mx terms.
Choose the policy for every other server. Keep your current one, or pick ~all, -all or ?all.
Copy the record. If your domain already has one, the new record keeps every existing term in its original order and you replace the old record with it.
Optionally, describe what sends email for you in plain words. AI maps the description to providers from the verified list, and you choose which to add.
Publish It
| Field | Value |
|---|---|
| Type | TXT |
| Host | @ (the domain itself), never _spf |
| Value | The record, starting with v=spf1 |
| TTL | 3600 |
A domain may publish only one record starting with v=spf1. Edit the existing one instead of adding a second. A record longer than 255 characters has to be stored as several quoted strings; the tool shows that form when you need it.
Read The Check Tab
- Lookups: receivers stop after 10 DNS lookups, counting every include, a, mx, ptr, exists and redirect, nested ones too (RFC 7208 §4.6.4).
- Empty lookups: more than two lookups that return nothing also fail the record.
- Lookup tree: each line shows its own lookup plus the ones nested under it, so you can see which include is expensive.
- Issues: each one names the term involved and what to change. DNS that does not answer is reported as a temporary failure, not as a missing record.
Test A Sending IP
Test An IP runs the same evaluation a receiving server runs: enter the server's IP, the sender address and optionally the HELO name, and you get pass, fail, softfail, neutral, none, permerror or temperror, plus the term that decided it and every term evaluated.
Get Under The Limit
Remove includes your domain does not need. The tool lists the ones that send with their own return-path.
Remove senders you no longer use.
Move a bulk sender to a subdomain, which has its own record and its own 10 lookups.
Flatten an include only as a last resort. The tool replaces it with the addresses it has today and re-checks the result. It refuses Microsoft 365, which Microsoft says not to flatten, and any include whose answer depends on the message (exists, ptr or macros).
SPF In SendCanyon
Every sending domain in SendCanyon is checked under Senders → Domains: SPF, DKIM and DMARC, with the same lookup and duplicate-record checks. A verified domain is re-checked every six hours, and you are told if it stops passing.
Was this page helpful?
Related articles
- Free Tools OverviewWhat the free tools are, where to find them on the website and in the app, how AI helps and what each use keeps.Free Tools
- Quick start: zero to first campaignThe six steps between creating a workspace and launching your first sequence, and how long each one really takes.Getting Started
- Add and verify a domainWalk through each generated DNS record, where to paste it at common registrars, and what to do while propagation runs.Domains & DNS