How SPF works
Email was designed without a way to check who is sending. Any server can claim to send for any domain. SPF fixes one part of that: the domain owner lists the servers that are really theirs, and receivers check each incoming connection against the list.1
- The domain publishes a record. It is a TXT record in DNS that starts with
v=spf1. - A message arrives. The receiving server notes the IP address it came from and the domain in the bounce address, also called the envelope sender or Return-Path.
- The receiver looks up that domain’s SPF record and checks whether the IP address is covered by it.
- The result is recorded as pass, fail, softfail, neutral or an error, and the receiver uses it when deciding what to do with the message.
How to read an SPF record
A typical record looks like this: v=spf1 ip4:203.0.113.10 include:_spf.example.net -all. It is read left to right, and whichever part matches first decides the result.
| Part | What it means |
|---|---|
| v=spf1 | Marks the record as SPF, version 1 |
| ip4: and ip6: | An IP address or range that may send |
| a and mx | The servers the domain’s own A or MX records point to |
| include: | Also accept whatever another domain’s SPF record allows, used for outside sending services |
| -all | Fail everything else. Only the listed servers send for this domain |
| ~all | Softfail everything else. Probably not allowed, so treat with suspicion |
Two rules trip people up. A domain may have only one SPF record, and two records produce an error instead of being merged. A record may also trigger at most 10 further DNS lookups, so long chains of include: entries can break it.1
Why SPF matters
Without SPF, a receiver has no simple way to tell a company’s real mail server from a stranger’s. With it, mail from an unlisted server stands out at once. Large providers now expect it: Gmail requires every sender to set up SPF or DKIM, and both for bulk senders, those sending around 5,000 or more messages a day.2
What SPF doesn’t cover
- The address you see. SPF checks the hidden bounce address, not the From line shown in your mail app. A forger can pass SPF for their own domain while showing yours. DMARC closes that gap.
- Forwarding. When mail is forwarded, it arrives from the forwarder’s server, which isn’t on the original domain’s list, so SPF often fails. A DKIM signature survives the trip.
- The content. SPF says nothing about whether the message was changed on the way.
Where you’ll see SPF
You meet SPF in two places. When you set up email on your own domain, your provider gives you an SPF record to add at your DNS host. And in the headers of any email you receive, your provider writes the result on the Authentication-Results line, for example spf=pass. You can look up any domain’s record yourself with dig +short TXT example.com.
SPF in Secria
The SPF record for secria.me ends in -all, so receivers are told to fail mail from any server that isn’t ours. When you connect your own domain on Mail Plus or Secria Pro, Secria shows you the SPF record to add, along with the MX, DKIM and DMARC records, each with a copy button, and checks them for you.
Related terms
Sources
- IETF, RFC 7208: Sender Policy Framework (SPF) for Authorizing Use of Domains in Email, Version 1 (April 2014).
- Google, Email sender guidelines (Google Workspace Admin Help).
Checked October 2026. Secria’s own records are public in DNS and were read on 11 October 2026. Other Secria facts are from our Mail and VPN pages.
Questions about SPF
Is SPF enough to stop email spoofing?
No. SPF checks the hidden bounce address, not the From address people see. To protect the visible address you need DMARC, which builds on SPF and DKIM.
What is the difference between -all and ~all?
Both cover every server not listed in the record. With -all the result is a fail, a clear statement that the server may not send. With ~all the result is a softfail, a weaker signal that receivers usually treat as suspicious without rejecting.
Why does SPF fail on forwarded email?
SPF looks at the server that delivered the message. A forwarded message comes from the forwarding service, which isn’t on the original sender’s list. That is why domains also sign with DKIM, which stays valid when mail is forwarded unchanged.
Can a domain have more than one SPF record?
No. The standard allows one SPF record per domain, and a second one causes an error. If several services send for you, list them all in the same record.