XiaTools
Email tool

SPF Record Generator

Create a correct SPF record in seconds by selecting the services that send email for your domain.

Create your SPF record

Managing email authentication can quickly become complex when you use multiple third-party services to send messages on behalf of your domain. The XiaTools SPF Record Generator simplifies this process by letting you select your email providers to build a correct Sender Policy Framework record in seconds. This ensures receiving mail servers can easily verify your authorized senders and block unauthorized emails from spoofing your brand.

What is it

An SPF record is a specially formatted TXT record published in your domain's Domain Name System (DNS) zone. It contains a list of all IP addresses and third-party services that are officially permitted to send emails using your domain name in the Return-Path or From addresses. When a receiving mail server gets an incoming message, it looks up your domain's DNS records, checks the sender's IP against your SPF policy, and decides whether to accept, quarantine, or reject the email. The XiaTools SPF Record Generator is a free utility designed to construct this exact cryptographic policy string without requiring you to manually memorize complex modifier syntax and mechanism rules.

Why it matters

Without a properly configured SPF record, major email providers like Google and Microsoft will often flag your outgoing messages as spam or reject them outright, severely hurting your email deliverability. Cybercriminals actively exploit domains lacking robust email authentication to launch phishing campaigns, which can permanently damage your brand reputation and domain trustworthiness. Furthermore, mailbox providers now enforce strict authentication standards for bulk senders, making a valid SPF setup mandatory rather than optional for reliable business communications.

How to use this tool

  1. Locate the input field on the XiaTools SPF Record Generator page and enter your primary domain name (for example, example.com).
  2. Select your inbound and outbound email service providers from the provided list, such as Google Workspace, Microsoft 365, Mailgun, or Zendesk.
  3. Add any custom sending server IP addresses (IPv4 or IPv6) or external domain include mechanisms required by your custom infrastructure.
  4. Choose your strictness policy for unauthorized emails, selecting between a soft fail (~all) or a hard fail (-all) depending on your current deployment stage.
  5. Click the Check or Generate button to compile your inputs into a finalized, ready-to-use TXT record string.

How to read the results

Once generated, the tool outputs a complete DNS TXT record string that you must copy and paste into your DNS management console. For example, a typical output for example.com might look like v=spf1 include:_spf.google.com ip4:192.0.2.1 -all.

The v=spf1 tag defines the version of the SPF specification being utilized, which must always appear at the very beginning of the record. The include:_spf.google.com mechanism authorizes Google Workspace servers to send email on behalf of your domain by referencing Google's own secondary SPF records. The ip4:192.0.2.1 mechanism explicitly whitelists a single specific IPv4 address associated with your local mail transfer agent or dedicated server. The ending mechanism, -all, acts as the strict enforcement rule, instructing receiving mail servers to hard-fail and reject any email originating from an IP address not explicitly listed in the record.

Common problems and how to fix them

Exceeding the DNS Lookup Limit

The SPF specification strictly limits the total number of DNS lookup mechanisms—such as include, a, mx, and exists—to a maximum of 10 per evaluation. If you exceed this limit, receiving servers return a permanent error, causing legitimate emails to fail authentication. To fix this, remove redundant third-party services, flatten nested include statements where possible, or use specialized SPF flattening tools to resolve domain names into static IP addresses.

Multiple SPF Records on a Single Domain

A single domain or subdomain can only have one active SPF record; publishing two or more TXT records starting with v=spf1 creates a neutral or permerror result, breaking validation entirely. To fix this, log into your DNS host, delete all conflicting TXT records, and consolidate all authorized providers and IP ranges into a single, comprehensive SPF string.

Syntax and Typo Errors

A simple missing colon, misplaced space, or misspelled mechanism name (like writing ip4s instead of ip4) will invalidate the entire security policy. To fix this, always copy the exact output provided by our generator without altering punctuation, and ensure your DNS host accepts the record as a standard TXT type.

Best practices

Always test your generated SPF record using a diagnostic lookup tool before publishing it to your live DNS zone to catch formatting errors early. Start your deployment phase using the soft-fail policy (~all) to monitor email delivery reports and ensure legitimate services are not accidentally blocked, then upgrade to a hard fail (-all) once your infrastructure is stable. Remember to review your authorized providers at least quarterly to remove old services and add new marketing or transactional email platforms as your business grows.

Frequently asked questions

What is an SPF record?

An SPF record is a TXT record published in your DNS settings that specifies which mail servers and IP addresses are authorized to send emails on behalf of your domain name.

Why do I need the XiaTools SPF Record Generator?

Building an SPF record manually can lead to syntax errors or broken lookups. This generator automatically formats your chosen providers into a valid string to ensure high email deliverability.

How many SPF records can a domain have?

A domain or subdomain must only have one active SPF record. Having multiple records causes validation errors and prevents receiving servers from authenticating your emails.

What is the 10-lookup limit in SPF?

The SPF protocol allows a maximum of 10 DNS lookup mechanisms per record evaluation. Exceeding this limit results in a permanent lookup error and delivery failures.

Should I use ~all or -all at the end of my SPF record?

-all enforces a strict hard fail for unauthorized emails, while ~all applies a soft fail, which flags unauthorized mail as spam rather than outright rejecting it.

Where do I add the generated SPF record?

You must copy the generated TXT record string and add it to your domain's DNS manager under the root domain or designated subdomain as a TXT type record.

SPF Record Generator guides

Related tools