SPF and DMARC record builder
Two short lines in your DNS zone decide which servers may send mail as your domain and what happens to everyone else who tries. Answer a few questions and the builder writes both lines as you go.
SPF
Tick everything that puts your domain in a From line: the mailbox service, the newsletter platform, the billing or help desk app, the web server behind your contact form.
For a sender that is not listed above: paste the ip4:, ip6: or include: terms it gave you, with a space between each.
Mailchimp is absent on purpose. It passes DMARC through DKIM, which you switch on in its domain settings, and needs no SPF term.
DMARC
Your instruction to receivers for mail that uses your domain and passes neither check, plus the mailbox where they report what they saw.
Use a mailbox made for this: each large receiver sends one XML file a day. No address, no reports.
DNS changes take from a few minutes to a few hours to spread. After that, confirm both records with the SPF, DKIM and DMARC checkup.
What’s inside the two records
Both are TXT records, the free-text type of DNS entry. An SPF record is read from left to right, and the first term that matches the sending server wins:
v=spf1 include:_spf.google.com include:sendgrid.net ip4:203.0.113.5 ~all
v=spf1- Marks the record as SPF. It has to come first.
include:- Imports the server list a provider keeps up to date for its customers. You never have to know its IP addresses.
ip4:,ip6:- One address or a range, for a server you run yourself.
mx,a- Whatever machines your MX records or your website’s address point to at the moment.
~allor-all- The verdict for every other server: soft fail (accept with suspicion) or fail.
A DMARC record is a list of tags separated by semicolons, published under the name _dmarc:
v=DMARC1; p=none; rua=mailto:dmarc@example.com;
p= is the policy for mail that fails, and rua= is where receivers send their daily summary.
How the builder puts them together
Each box you tick adds one term. The list holds fifteen common senders, from Google Workspace and Microsoft 365 to SendGrid, Amazon SES and Shopify, each with the include published in its documentation. The free field takes ip4:, ip6: and include: terms, and if you type a bare host name it’s turned into an include.
The builder counts one DNS lookup for each include, mx and a, and starts warning at seven. SPF allows ten in total, and most includes contain further includes that the builder can’t see from your browser.
If you tick nothing, you get v=spf1 -all, and the DMARC policy is raised from none to reject. That pair is the right setup for a domain that sends no mail at all.
The domain you type is only used to display the record names and to prepare the link to the checkup. It never leaves the page.
Entering the records at your DNS host
Open the DNS zone wherever your name servers are, which could be your registrar, Cloudflare or the hosting company. Add two TXT records.
| Record | Name or host field | Value |
|---|---|---|
| SPF | @, or left empty, or the domain itself | The line starting with v=spf1 |
| DMARC | _dmarc | The line starting with v=DMARC1 |
Most control panels add the domain for you, so typing _dmarc.example.com would create _dmarc.example.com.example.com. Leave out the quotation marks unless the panel asks for them.
If there’s already a TXT record starting with v=spf1, edit that one. A second one makes both invalid. The same goes for _dmarc.
What the builder leaves to you
You won’t get DKIM here, because each sending service creates its own key pair. Look for “domain authentication” in its settings, where it gives you one to three CNAME or TXT records to add. It matters for DMARC, which passes when either SPF or DKIM succeeds under your own domain. Newsletter platforms often send with their own bounce address, so SPF doesn’t cover them and DKIM has to do the work.
Start with p=none. After two to four weeks of reports, opened with the DMARC report reader, you’ll know every source. Then move to quarantine and later reject, and from ~all to -all if you want.
The builder doesn’t read your current DNS, so it can’t tell you what’s already published or how many lookups your includes really cost. Once the records are live, run the SPF, DKIM and DMARC checkup, which follows every include and counts them.
Questions people ask
How do I create an SPF record for Google Workspace or Microsoft 365?
For Google Workspace alone: v=spf1 include:_spf.google.com ~all. For Microsoft 365 alone: v=spf1 include:spf.protection.outlook.com ~all. Add one include: for each other service that sends as your domain, all in the same record.
What should I put in the DMARC rua address?
A mailbox you create just for this, such as dmarc@yourdomain, or the address a report analysis service gives you. Expect one XML attachment a day from each large provider. An address on another domain only works if that domain publishes a record accepting your reports.
How long does a new SPF or DMARC record take to work?
A new record usually shows up within minutes. A changed record can keep being served from caches for as long as its previous TTL, often one hour and sometimes a day. You can follow it with the DNS propagation check.
Do I need SPF if I already have DKIM?
Either one satisfies DMARC, but Gmail and Yahoo ask bulk senders for both, and some receivers mark you down for a missing SPF record. Publish both.
Why is Mailchimp not in the list?
Mailchimp sends with its own return address, so an SPF term on your domain never gets evaluated for its mail. It passes DMARC through DKIM, once you’ve added the CNAME records shown on its domain authentication page.
Can I have separate SPF records for subdomains?
Yes. SPF is looked up at the exact domain of the return address, so news.example.com has its own record and its own ten lookups. Moving a heavy sender to a subdomain is a standard way to get under the limit.