How to publish your SPF record
- Open the DNS settings at your domain registrar or DNS host (Cloudflare, cPanel Zone Editor, your registrar's panel).
- Look for an existing TXT record that starts with
v=spf1. If there is one, edit it — a domain must have only one SPF record. - Otherwise create a TXT record with host
@and paste the generated value. - Wait for DNS to update (usually minutes, sometimes up to the record's TTL), then run the SPF Checker to confirm the real lookup count.
Keep it under 10 lookups
Each include, a, and mx costs at least one DNS lookup, and provider includes often hide more inside. Plain ip4/ip6 entries are free. If you're close to the limit, drop services you no longer use or move bulk mail to a subdomain with its own record.
SPF is step one
Receivers like Gmail also look for DKIM and a DMARC policy. Once SPF is live, set up DKIM in your email provider and create a policy with the DMARC Generator.
Frequently asked questions
At your DNS provider, create (or edit) a TXT record on the root of your domain — the host/name is usually "@". If an SPF record already exists, replace it instead of adding a second one.
Only if those servers actually send email. Each one costs a DNS lookup, and on most hosted mail setups the provider include already covers them.
Start with ~all (softfail) while you confirm every service is listed, then switch to -all (fail). Never publish +all.
Provider includes often contain more includes inside them. Run the SPF Checker after publishing to see the real total.