Free SPF Record Generator - Build SPF TXT Records
SPF (Sender Policy Framework) tells receiving mail servers which IP addresses and services are authorized to send email from your domain. Our free SPF record generator provides a visual mechanism builder that lets you add include, ip4, ip6, a, and mx mechanisms, tracks your DNS lookup count against the RFC 7208 10-lookup limit, validates syntax in real time, and outputs a copy-paste ready TXT record.
What This Tool Checks
Comprehensive analysis powered by Vysiro's scanning engines
Visual mechanism builder (include, ip4, ip6, a, mx)
Real-time DNS lookup counter (10-lookup limit)
Common provider presets (Google, Microsoft, SendGrid, etc.)
IP address and CIDR range validation
Qualifier selection (+, -, ~, ? for each mechanism)
All-mechanism policy selector (-all, ~all, ?all)
Syntax validation and error highlighting
Copy-paste ready TXT record output
How It Works
Get results in seconds with our automated scanning process
Start with the v=spf1 prefix (added automatically)
Add mechanisms: include for email services, ip4/ip6 for direct IPs, a/mx for domain resolution
Watch the DNS lookup counter to stay within the 10-lookup limit
Choose your all-mechanism qualifier: -all (hard fail) recommended for security
Review the generated SPF record and validate syntax
Copy the TXT record and add it to your domain's DNS zone
Frequently Asked Questions
Everything you need to know about spf record generator
What is an SPF record and why do I need one?
An SPF record is a DNS TXT record that lists which servers are allowed to send email from your domain. Without SPF, anyone can send email pretending to be from your domain. SPF is a foundational requirement for DMARC compliance and is checked by virtually all major email providers.
How do I know which mechanisms to add?
List every service that sends email on your behalf: your email provider (Google Workspace, Microsoft 365), marketing tools (Mailchimp, SendGrid), CRM systems (Salesforce, HubSpot), and any servers that send transactional email. Each service provides their SPF include domain in their documentation.
What is the SPF 10-lookup limit?
RFC 7208 limits SPF evaluation to 10 DNS lookups. Each include, a, mx, ptr, exists, and redirect mechanism counts as one lookup. Exceeding this limit causes a permerror, which means SPF fails and emails may be rejected. Our generator tracks lookups in real time to prevent this.
What is the difference between -all, ~all, and ?all?
The -all (hard fail) tells receivers to reject unauthorized email. The ~all (soft fail) marks it as suspicious but still delivers. The ?all (neutral) takes no position. Vysiro recommends -all for maximum security once all legitimate senders are listed.
Can I use ip4 and include mechanisms together?
Yes, you can mix any mechanism types. Use include for cloud email services and ip4/ip6 for your own mail servers with static IPs. Note that ip4 and ip6 mechanisms do not count toward the 10-lookup limit, making them efficient for authorizing specific servers.
How do I add Google Workspace to my SPF record?
Add the mechanism include:_spf.google.com to your SPF record. For Microsoft 365, use include:spf.protection.outlook.com. For SendGrid, use include:sendgrid.net. Our generator includes presets for common providers to make setup easy.
Related Free Tools
Continue your domain security analysis
SPF Validator
Validate SPF records, check DNS lookup limits, and resolve include chains.
Use toolSPF Flattener
Flatten SPF records by resolving all includes to IP addresses, eliminating DNS lookup limits.
Use toolDMARC Generator
Build DMARC TXT records with policy selection, reporting, and alignment configuration.
Use toolTrustScore
Get an instant composite trust score (0-1000) across 29 security categories.
Use toolGo Beyond Free Checks
Get continuous monitoring, automated fixes, proof packs, and API access. Protect your domains with Vysiro's agentless attack-surface monitor.