All tips
SPF 2 min read

Reading an SPF record, mechanism by mechanism

A walk through every mechanism and modifier you are likely to meet in a real SPF record.

SPF records are evaluated left to right. The first mechanism that matches the connecting IP decides the result, and evaluation stops there. Everything after a match is ignored, which is why order matters and why 'all' belongs at the end.

The mechanisms

  • ip4:203.0.113.0/24 matches an address or range.
  • ip6:2001:db8::/32 does the same for IPv6.
  • a matches the A/AAAA records of the current domain, or a:mail.example.com for another.
  • mx matches the addresses of the domain's MX hosts.
  • include:_spf.google.com evaluates another domain's SPF record and matches if that record passes.
  • exists:%{i}._spf.example.com matches if the constructed name resolves at all. Rare outside large senders.
  • all matches everything. Always last.

Qualifiers

Every mechanism can carry a qualifier: + for pass (the default, so it is usually omitted), - for fail, ~ for softfail, and ? for neutral. In practice you only ever write one explicitly, on the final all.

Modifiers

  • redirect=example.net replaces the whole record with another domain's. Only takes effect if no mechanism matched, and is ignored entirely if an all mechanism is present.
  • exp=explain.example.com supplies a human-readable explanation string for failures. Optional, and widely ignored.

The ptr mechanism is deprecated by RFC 7208 and should not be used. It is slow, it puts load on other people's DNS, and some receivers ignore it outright.

Paste a record into the SPF tool to see the mechanisms broken out with a running lookup count against the limit of ten.

Check your SPF record and lookup count
spfsyntaxdns