SPF, or Sender Policy Framework, is an email authentication mechanism that publishes which servers are authorized to send mail on behalf of a domain.
Why is SPF used?
Attackers can attempt to use a company’s domain as a sender address. SPF helps receiving mail systems determine whether the connecting server is authorized.
Where is an SPF record stored?
SPF information is published as a TXT record in the domain’s DNS zone. The record can authorize IP addresses or external email services.
What does the receiving server do?
When a message arrives, the receiver queries the sender domain’s SPF record and checks whether the sending system is permitted.
Is SPF enough by itself?
No. SPF is an important layer, but DKIM and DMARC provide additional authentication and policy capabilities.
Common SPF mistakes
- Publishing multiple SPF records for one domain
- Forgetting legitimate sending services
- Using overly broad authorization
- Ignoring DNS lookup limits
Read our broader SPF, DKIM and DMARC guide.