Help CenterOpen Distro

What is SPF and how does it work?

SPF is a DNS record listing the servers allowed to send email for your domain. Learn how it works, how to check it and how to set it up for Google Workspace.

Updated 3 min read

SPF (Sender Policy Framework) is a list, published in your DNS, of the servers allowed to send email for your domain. When an email arrives claiming to be from your domain, the receiving server checks that list. If the sending server is on it, SPF passes.

How SPF works

  1. You publish one TXT record on your domain (for example example.com) that starts with v=spf1.
  2. Someone receives an email whose sending domain is example.com.
  3. Their server looks up your SPF record and compares the server that delivered the email with the list.
  4. The result is a pass, fail, softfail or neutral, which feeds into spam filtering and into DMARC.

The record ends with an "all" rule telling receivers what to do with servers not on the list:

EndingMeaning
~allSoftfail: not on the list, treat with suspicion. A common, safe choice.
-allFail: not on the list, reject. Use once you are sure the list is complete.
?allNeutral: no opinion. Offers little protection.

What it means for Distro users

Distro sends through your own Google mailbox, so your emails leave from Google's mail servers. Your SPF record therefore needs to include Google.

  • Google Workspace on your own domain: add Google to your domain's SPF record. Google's documentation lists the include value to use.
  • Free @gmail.com address: Google manages SPF for gmail.com. There is nothing for you to set up.
  • Alias on a different domain: the alias's domain needs its own SPF record that covers the servers that send for it. See Send cold email from your custom-domain email.

Example record

This is an example for a domain that sends only through Google Workspace. Confirm the current value against Google's documentation before you publish it.

Type:  TXT
Host:  @   (your root domain, e.g. example.com)
Value: v=spf1 include:_spf.google.com ~all

If other services also send email as your domain (a help desk, a newsletter tool, your billing system), each needs its own include in the same record:

v=spf1 include:_spf.google.com include:servers.example-service.com ~all

The second include above is a placeholder. Use the value each service documents.

How to set it up

  1. Sign in to your DNS provider (often your domain registrar or hosting company).
  2. Look for an existing TXT record on the root domain that starts with v=spf1.
  3. If one exists, edit it and add Google's include before the all rule. If none exists, create one.
  4. Save. DNS changes can take from a few minutes to around 48 hours to spread.

How to check it

  • Run nslookup -type=txt example.com (Windows) or dig TXT example.com +short (macOS, Linux) and look for the v=spf1 line.
  • Send an email to a Gmail address, open it, choose Show original from the message menu and look for SPF: PASS.

Common mistakes

  • Two SPF records. A domain must have exactly one record starting with v=spf1. Two records cause SPF to fail. Merge them.
  • Too many lookups. SPF allows at most 10 DNS lookups. Each include can count for several. Remove services you no longer use.
  • Forgetting a sending service. Any tool sending as your domain must be in the record, or its emails fail SPF.
  • Typos such as include:_spf.gogle.com or a missing v=spf1.

SPF alone is not enough. It breaks when email is forwarded and checks a technical sender address rather than the From address people see. That is why you also need DKIM and DMARC.

Still stuck?

Email us at hello@usedistro.com with what you tried and what you see. Signed in? Help & support in the app has walkthrough videos and a message form.

Help & support