How to set up an SPF record

Create or correct your domain’s SPF record: the syntax, examples for Traxio and external services, the one-record rule and the 10-lookup limit.

How-to guideIntermediate2 min readUpdated

An SPF record lists the servers allowed to send email for your domain. Receiving servers check it and treat mail from anywhere else with suspicion.

Your SPF record on Traxio

With Traxio nameservers, DirectAdmin creates an SPF record automatically. Check it in Account Manager then DNS Management: look for a TXT record on the domain beginning v=spf1.

A typical record for mail sent only through Traxio:

v=spf1 a mx ~all

Reading SPF

PartMeaning
v=spf1This is an SPF record
aThe server in the domain’s A record may send
mxThe domain’s MX servers may send
ip4:203.0.113.10This specific address may send
include:_spf.example.comWhatever that provider’s SPF allows may send
~allAnything else: soft fail (accept but mark)
-allAnything else: fail

Adding other senders

If you also send through a newsletter service, Google Workspace or a CRM, add their include: to the same record:

v=spf1 a mx include:_spf.google.com include:servers.mcsv.net ~all

Use the include value each service documents.

The rules that break SPF

  • Only one SPF record. Two TXT records starting v=spf1 make SPF fail entirely. Merge them.
  • At most 10 DNS lookups. Each include, a, mx and redirect costs lookups, and includes can contain more. Exceed 10 and SPF fails with a “permerror”. Remove services you no longer use.
  • ~all or -all, never +all. +all allows anyone to send as you.

Editing it

  1. Open Account Manager then DNS Management.
  2. Edit the existing v=spf1 TXT record — don’t add a second.
  3. Save, then check:
dig yourdomain.co.uk TXT +short

Popular

Tip: press / to search from any pageSee all results