FM 8-02 Chapter 8 · Email and identity
SPF record
Explain an SPF record term by term, or look up a domain and count its DNS lookups against the limit of 10.
Network Sends data to cloudflare-dns.com, dns.google: the TXT, A and MX names of the domain and its includes, only when you press Look up. Only when you press the button.
- Lookups in this record
- 2 of 10 (includes count their own lookups too)
- Default result
- softfail
- v=spf1 Version: this TXT record is an SPF policy.
- ip4:192.0.2.0/24 pass If the sender's IP is in 192.0.2.0/24: pass: allowed to send. No lookup needed.
- include:_spf.example.net pass 1 lookup If _spf.example.net's SPF record passes for the sender: pass: allowed to send. Costs one lookup plus whatever that record costs.
- mx pass 1 lookup If the sender's IP is an address of one of the MX hosts of the domain being checked: pass: allowed to send. Each MX host is looked up too (at most 10).
- ~all softfail Everything not matched before: softfail: probably not allowed, accept but mark.
To count nested lookups, enter just the domain name: the tool then fetches the record and every include over DNS over HTTPS.
SPF lists the servers allowed to send mail with this domain in the envelope sender (Return-Path). Receivers stop at the first matching term. RFC 7208 allows 10 terms that need DNS (include, a, mx, ptr, exists, redirect) across the whole tree, and 2 lookups that return nothing. ip4, ip6 and all are free. Explaining a pasted record never touches the network.