Guide · SPF
With SPF (Sender Policy Framework) you define in DNS which servers may send email on behalf of your domain. If the record is missing or broken, your emails end up in spam – or forgers have an easy job. Mailsecurity24 checks your SPF record completely, counts DNS lookups across all levels and shows in your DMARC reports which of your senders actually pass SPF.
An SPF record is a TXT record on your domain that starts with v=spf1. It lists the permitted senders – such as your mail server, Microsoft 365 or a newsletter service – and ends with a rule for everyone else: -all (reject) or ~all (mark as suspicious). The receiving server compares the sender’s IP address with this list. Important: SPF checks the technical sender address (Return-Path), not the address your recipients see. Only DMARC links the two.
Good to know: A domain may have only one SPF record. Two records starting with v=spf1 make SPF fail completely at many recipients.
List every service that sends email with your domain: mail server, Microsoft 365 or Google Workspace, newsletters, shop, CRM and accounting. The DMARC reports in Mailsecurity24 also show the senders you forgot.
Combine all senders in one record, for example v=spf1 mx include:spf.protection.outlook.com -all. Make sure you need no more than ten DNS lookups.
Publish the record as a TXT record on your domain and check it with the domain check. Mailsecurity24 then monitors it daily and reports every change.
Most SPF problems are invisible: the record looks correct but still fails at recipients. Mailsecurity24 detects these errors automatically:
Good to know: SPF fails on forwarding because the forwarding server is not listed in your record. That is why you also need DKIM – and DMARC, which combines both results.
Free domain check
In seconds we check DMARC, SPF, DKIM, MX, MTA-STS, TLS reporting and BIMI for your domain – free and without signing up.
With -all (hard fail) you tell recipients that no server other than those listed may send email for your domain. ~all (soft fail) only marks such messages as suspicious. With DMARC in place, ~all is usually enough because DMARC makes the actual decision; without DMARC, -all is the stricter choice.
No. SPF only checks the technical sender address and fails on forwarding. Effective protection against forged senders only comes from combining SPF, DKIM and DMARC.
Ten at most. Every include, a, mx, ptr and exists counts – including nested records of the services you include. If the limit is exceeded, many recipients treat SPF as an error (permerror).
Yes. With v=spf1 -all you declare that no email comes from this domain. In Mailsecurity24 you can park such domains: we show the right protective records and check them continuously.
Try Mailsecurity24 free for 14 days. No payment details required.
