XiaTools

Can You Have Multiple SPF Records? The Definitive Answer

Updated 11 Oct 2026

No, you cannot have multiple SPF (Sender Policy Framework) records for a single domain. If a receiving mail server encounters more than one SPF TXT record during a DNS lookup, the validation immediately fails with a permanent error known as a PermError. This means your legitimate emails may be rejected, marked as spam, or dropped entirely before they ever reach an inbox.

To diagnose your current configuration, run your domain through the Email Security Checker to instantly identify multiple SPF records, syntax errors, and missing security tags.

The Technical Problem: Why Multiple SPF Records Fail

When a mail server receives an email claiming to be from example.com, it queries the Domain Name System (DNS) for the domain's TXT records to find the policy defining which servers are authorized to send mail.

According to the official RFC 7208 specification for SPF, if a DNS lookup returns multiple records that look like SPF policies, the evaluator must treat this as a fatal error. The exact rule states that the domain MUST NOT result in more than one record. When a receiving server sees two or more records, it cannot guess which one is correct or merge them securely. As a result, it aborts the check and returns a PermError status code.

What Happens During a PermError

When a PermError occurs, the receiving mail server's anti-spam engine reacts based on its local configuration. Common behaviors include:

  • Immediate Rejection: The mail server rejects the message during the SMTP handshake with a 5xx error code, forcing a bounce back to the sender.
  • Spam Quarantine: The email bypasses the inbox entirely and lands in the spam or junk folder.
  • DMARC Failure: If you have DMARC enabled, an SPF PermError breaks SPF alignment. If your DKIM is also misconfigured or missing, your DMARC check fails, leading to domain spoofing vulnerabilities and delivery failure.

How to Combine Multiple Services Into One SPF Record

Many domain administrators accidentally create multiple SPF records when adopting third-party SaaS tools. For example, you might set up Google Workspace for corporate email, add Mailchimp for newsletters, and integrate Zendesk for customer support. Each service tells you to add an SPF record, tempting you to create three separate TXT entries.

Instead, you must merge all authorized senders into a single, cohesive TXT record using mechanism tags like include, ip4, and ip6.

Step-by-Step: Merging Your SPF Records

Imagine you currently have these three separate (and broken) DNS entries:

  1. v=spf1 include:_spf.google.com ~all
  2. v=spf1 include:servers.mcsv.net ~all
  3. v=spf1 include:mail.zendesk.com ~all

To fix this, you combine them into a single TXT record placed at your domain's root (@ or example.com).

TXT   example.com   v=spf1 include:_spf.google.com include:servers.mcsv.net include:mail.zendesk.com ~all

Rules for a Valid Consolidated Record

  • Single Declaration: The string v=spf1 must appear only once, right at the very beginning of the record.
  • Single Terminator: The qualifier tag (usually ~all or -all) must appear only once, at the very end of the record.
  • Order Matters: While mechanisms are evaluated sequentially, putting your most frequent senders first is standard practice for readability.

Verification and Troubleshooting Commands

Before deploying your changes, or to confirm whether you currently suffer from the multiple SPF record issue, use command-line tools or PowerShell to inspect your DNS TXT records.

Using Dig on Linux and macOS

Open your terminal and run the dig utility to query TXT records for your domain:

dig example.com TXT

Look through the answer section in the output:

;; ANSWER SECTION:
example.com.		300	IN	TXT	"v=spf1 include:_spf.google.com ~all"
example.com.		300	IN	TXT	"v=spf1 include:mail.zendesk.com ~all"

Diagnosis: If you see more than one line starting with v=spf1, you have multiple SPF records and must consolidate them immediately.

Using PowerShell on Windows

If you are on Windows, use PowerShell to query the DNS records:

Resolve-DnsName -Name example.com -Type TXT

Review the Strings property in the output to ensure only one SPF policy exists.

SPF Record Limitations to Watch Out For

Consolidating multiple services into a single record introduces a new challenge: the 10-DNS-lookup limit.

RFC 7208 limits SPF evaluation to a maximum of 10 DNS-mechanisms that require a lookup (such as include, a, mx, ptr, and exists). If your combined record forces the receiving server to perform 11 or more lookups, the evaluation terminates with a PermError.

Example of a Lookup-Heavy Record

v=spf1 include:spfa.example.com include:spfb.example.com include:spfc.example.com ~all

If each of those included domains contains three more lookups, you quickly exceed the limit.

  • Fix: Flatten your SPF records or use IP ranges (ip4: and ip6:) directly if the third-party provider's IPs are static and well-documented (e.g., ip4:192.0.2.0/24).

Comparison: Multiple Records vs. Single Consolidated Record

Feature Multiple SPF Records Single Consolidated Record
DNS Syntax Two or more TXT records starting with v=spf1 One TXT record starting with v=spf1
Mail Server Behavior Triggers PermError, mail rejected or spammed Successfully evaluates authorized senders
DMARC Compliance Fails SPF alignment Passes or fails correctly based on sending IP
Deliverability Poor (often 0% delivery to major providers) Excellent (maintains inbox placement)

Common Mistakes and How to Fix Them

  • Mistake 1: Creating separate records for subdomains and root.
    • Fix: Your root domain (example.com) and your mail-sending subdomains (mail.example.com) require independent SPF records. A record on the root does not cover subdomains.
  • Mistake 2: Forgetting to remove old provider records.
    • Fix: When you cancel a service like Mailchimp or Zendesk, remember to remove their include: statement from your SPF record to free up DNS lookup slots.
  • Mistake 3: Using the deprecated ptr mechanism.
    • Fix: Avoid ptr entirely. It is slow, discouraged by the RFC, and counts against your lookup limit.

Quick Checklist for SPF Health

  • Check that your domain has exactly one TXT record beginning with v=spf1.
  • Ensure all third-party email tools are added using include: statements within that single record.
  • Verify that your total DNS lookup count (including nested includes) is 10 or fewer.
  • Conclude the record with a strict policy tag such as ~all (softfail) or -all (hardfail).
  • Test the final configuration using the Email Security Checker tool.

Frequently asked questions

What happens if I have two SPF records?

When a receiving mail server finds more than one SPF record for a domain, it cannot determine which one is authoritative. It immediately stops the evaluation and returns a Permanent Error (PermError), which usually results in the email being rejected or sent to the spam folder.

Can I use multiple TXT records if one is for SPF and one is for DMARC?

Yes. DMARC uses a separate TXT record starting with `v=DMARC1` usually placed at `_dmarc.example.com`, while SPF uses `v=spf1` at the root domain `example.com`. Having one SPF record and one DMARC record is completely correct and necessary.

How do I add multiple email services to my SPF record?

You combine them into a single TXT record by appending multiple `include:` mechanisms. For example, you can include Google Workspace and Mailchimp in one line: `v=spf1 include:_spf.google.com include:servers.mcsv.net ~all`.

What is the 10-lookup limit in SPF?

The SPF specification restricts mail servers from performing more than 10 DNS lookups (triggered by mechanisms like include, a, mx, and ptr) during evaluation. Exceeding this limit causes a PermError, even if you only have a single SPF record.

Should my SPF record end with ~all or -all?

Ending with `~all` (SoftFail) marks unauthorized emails as suspicious, making it safer during initial setup. Ending with `-all` (HardFail) instructs receiving servers to strictly reject emails from unauthorized sources, but requires absolute confidence in your IP list to avoid blocking legitimate mail.

Free tools