Can You Have Multiple SPF Records? The Definitive Answer
No, you cannot have multiple SPF (Sender Policy Framework) records for a single domain. If a receiving mail server encounters more than one SPF TXT record during a DNS lookup, the validation immediately fails with a permanent error known as a PermError. This means your legitimate emails may be rejected, marked as spam, or dropped entirely before they ever reach an inbox.
To diagnose your current configuration, run your domain through the Email Security Checker to instantly identify multiple SPF records, syntax errors, and missing security tags.
The Technical Problem: Why Multiple SPF Records Fail
When a mail server receives an email claiming to be from example.com, it queries the Domain Name System (DNS) for the domain's TXT records to find the policy defining which servers are authorized to send mail.
According to the official RFC 7208 specification for SPF, if a DNS lookup returns multiple records that look like SPF policies, the evaluator must treat this as a fatal error. The exact rule states that the domain MUST NOT result in more than one record. When a receiving server sees two or more records, it cannot guess which one is correct or merge them securely. As a result, it aborts the check and returns a PermError status code.
What Happens During a PermError
When a PermError occurs, the receiving mail server's anti-spam engine reacts based on its local configuration. Common behaviors include:
- Immediate Rejection: The mail server rejects the message during the SMTP handshake with a 5xx error code, forcing a bounce back to the sender.
- Spam Quarantine: The email bypasses the inbox entirely and lands in the spam or junk folder.
- DMARC Failure: If you have DMARC enabled, an SPF
PermErrorbreaks SPF alignment. If your DKIM is also misconfigured or missing, your DMARC check fails, leading to domain spoofing vulnerabilities and delivery failure.
How to Combine Multiple Services Into One SPF Record
Many domain administrators accidentally create multiple SPF records when adopting third-party SaaS tools. For example, you might set up Google Workspace for corporate email, add Mailchimp for newsletters, and integrate Zendesk for customer support. Each service tells you to add an SPF record, tempting you to create three separate TXT entries.
Instead, you must merge all authorized senders into a single, cohesive TXT record using mechanism tags like include, ip4, and ip6.
Step-by-Step: Merging Your SPF Records
Imagine you currently have these three separate (and broken) DNS entries:
v=spf1 include:_spf.google.com ~allv=spf1 include:servers.mcsv.net ~allv=spf1 include:mail.zendesk.com ~all
To fix this, you combine them into a single TXT record placed at your domain's root (@ or example.com).
TXT example.com v=spf1 include:_spf.google.com include:servers.mcsv.net include:mail.zendesk.com ~all
Rules for a Valid Consolidated Record
- Single Declaration: The string
v=spf1must appear only once, right at the very beginning of the record. - Single Terminator: The qualifier tag (usually
~allor-all) must appear only once, at the very end of the record. - Order Matters: While mechanisms are evaluated sequentially, putting your most frequent senders first is standard practice for readability.
Verification and Troubleshooting Commands
Before deploying your changes, or to confirm whether you currently suffer from the multiple SPF record issue, use command-line tools or PowerShell to inspect your DNS TXT records.
Using Dig on Linux and macOS
Open your terminal and run the dig utility to query TXT records for your domain:
dig example.com TXT
Look through the answer section in the output:
;; ANSWER SECTION:
example.com. 300 IN TXT "v=spf1 include:_spf.google.com ~all"
example.com. 300 IN TXT "v=spf1 include:mail.zendesk.com ~all"
Diagnosis: If you see more than one line starting with v=spf1, you have multiple SPF records and must consolidate them immediately.
Using PowerShell on Windows
If you are on Windows, use PowerShell to query the DNS records:
Resolve-DnsName -Name example.com -Type TXT
Review the Strings property in the output to ensure only one SPF policy exists.
SPF Record Limitations to Watch Out For
Consolidating multiple services into a single record introduces a new challenge: the 10-DNS-lookup limit.
RFC 7208 limits SPF evaluation to a maximum of 10 DNS-mechanisms that require a lookup (such as include, a, mx, ptr, and exists). If your combined record forces the receiving server to perform 11 or more lookups, the evaluation terminates with a PermError.
Example of a Lookup-Heavy Record
v=spf1 include:spfa.example.com include:spfb.example.com include:spfc.example.com ~all
If each of those included domains contains three more lookups, you quickly exceed the limit.
- Fix: Flatten your SPF records or use IP ranges (
ip4:andip6:) directly if the third-party provider's IPs are static and well-documented (e.g.,ip4:192.0.2.0/24).
Comparison: Multiple Records vs. Single Consolidated Record
| Feature | Multiple SPF Records | Single Consolidated Record |
|---|---|---|
| DNS Syntax | Two or more TXT records starting with v=spf1 |
One TXT record starting with v=spf1 |
| Mail Server Behavior | Triggers PermError, mail rejected or spammed |
Successfully evaluates authorized senders |
| DMARC Compliance | Fails SPF alignment | Passes or fails correctly based on sending IP |
| Deliverability | Poor (often 0% delivery to major providers) | Excellent (maintains inbox placement) |
Common Mistakes and How to Fix Them
- Mistake 1: Creating separate records for subdomains and root.
- Fix: Your root domain (
example.com) and your mail-sending subdomains (mail.example.com) require independent SPF records. A record on the root does not cover subdomains.
- Fix: Your root domain (
- Mistake 2: Forgetting to remove old provider records.
- Fix: When you cancel a service like Mailchimp or Zendesk, remember to remove their
include:statement from your SPF record to free up DNS lookup slots.
- Fix: When you cancel a service like Mailchimp or Zendesk, remember to remove their
- Mistake 3: Using the deprecated
ptrmechanism.- Fix: Avoid
ptrentirely. It is slow, discouraged by the RFC, and counts against your lookup limit.
- Fix: Avoid
Quick Checklist for SPF Health
- Check that your domain has exactly one TXT record beginning with
v=spf1. - Ensure all third-party email tools are added using
include:statements within that single record. - Verify that your total DNS lookup count (including nested includes) is 10 or fewer.
- Conclude the record with a strict policy tag such as
~all(softfail) or-all(hardfail). - Test the final configuration using the Email Security Checker tool.