Back to all tools
Record builder SPF · DKIM · DMARC · MTA-STS · 100% client-side

SPF Record Generator

Build a valid SPF, DMARC, DKIM or MTA-STS record from a form, then paste it into your DNS. Everything is assembled in your browser, nothing you type here is sent anywhere, including to us.

Your record
.
Type
TXT
Host
.
Value
.
TTL
3600

Host names are shown the way most DNS panels expect them. A few providers want the full name including your domain, if yours shows an existing record as _dmarc.yourdomain.com rather than _dmarc, use the full form.

Questions people ask

How many DNS lookups can an SPF record use?

Ten. Every include, a, mx, exists and redirect mechanism costs at least one. Cross the limit and receivers return PermError, which many treat as a hard authentication failure. The generator counts as you add providers and warns before you cross it.

Can I have two SPF records?

No. A domain must publish exactly one SPF record. Two records is an automatic PermError at every receiver. If you already have one, merge the new include into it rather than adding a second TXT.

Should I end with ~all or -all?

Start with ~all (softfail) while you confirm every legitimate sender is in the record, then consider -all. Moving straight to -all with a sender missing silently drops that mail.