Email Fix Pack

SPF for multiple email providers: one merged record

A domain must not publish several SPF records. RFC 7208 says a domain must not have multiple records that would cause an authorization check to select more than one. When you use several senders, merge them into one record.

Steps

  1. List every service that sends mail as your domain, and ask each one for the SPF include it documents (many use DKIM-only setups that need no SPF change).
  2. Start from your mailbox provider. Google documents v=spf1 include:_spf.google.com ~all for Workspace, and for combining with Microsoft 365 shows:
    v=spf1 include:_spf.google.com include:spf.protection.outlook.com ~all
  3. Add each further provider's documented include before the final ~all, in the same record:
    v=spf1 include:_spf.google.com include: ~all
    Use only the include value your provider publishes; do not guess it.
  4. Delete any older second v=spf1 TXT record so only one remains.
  5. Count lookups: each include, a, mx, ptr, exists and redirect counts toward RFC 7208's limit of 10, and nested includes count too. Over 10 gives a permerror. See SPF too many DNS lookups.

Check your domain

Not sure what your domain publishes today? The checker reads your live DNS and shows what is missing. If you would rather skip the trial and error, the $29 Email Fix Pack gives you ready-to-paste records for your domain; see a sample pack.

Check your domain free

Sources

  • Google: Set up SPF
  • RFC 7208 (SPF)

More email delivery fixes

Email Fix Pack

Terms · Privacy · Refunds