Email & SMTP

Fix SPF Record

Correct a broken, too-permissive or over-the-limit SPF record so your mail authenticates properly.

The Problem

Your SPF record is rejecting legitimate mail, has too many DNS lookups, or was copy-pasted from somewhere and includes services you don't even use — and every sender you add makes the risk of it silently failing worse.

About this problem

Most broken SPF records aren't broken from day one — they degrade as services are bolted on without anyone removing what's no longer used, until the record either exceeds the 10-lookup limit or ends up authorising senders that have nothing to do with the business any more.

This typically gets fixed after a deliverability problem is traced back to SPF, after a security review flags an overly broad record, or right after adding a new sending tool pushes an already-borderline record over the limit.

What's Included

What's NOT Included

How It Works

  1. Audit every mechanism in the current record against services actually in use today.
  2. Flatten or remove redundant includes to bring the record back under the 10 DNS lookup limit.
  3. Rebuild the record with only confirmed, active senders, using the correct qualifier (~all vs -all) for your risk tolerance.
  4. Publish the corrected TXT record and confirm it replaces (not duplicates) the old one.
  5. Send a real test email through each major sending source and confirm SPF passes in the received headers.

In practice: you buy the service, send over whatever access or details the job needs, I investigate and do the work, and you confirm it's resolved before we call it done.

Frequently Asked Questions

How do I fix a failing SPF record?
Identify which mechanism is causing the failure (too many lookups, a missing sender, or a syntax error), then rebuild the record correctly and republish it as a single TXT record at the domain root.
Why is my SPF record still failing after I fixed it?
DNS changes take time to propagate, and some mail servers cache the old record for hours — if it's been corrected and still fails after 24-48 hours, there's usually a second, unrelated issue.
Should I use ~all or -all in my SPF record?
~all (softfail) is the safer starting point since it flags unauthorised mail without outright rejecting it; -all (hardfail) is stricter but risks blocking legitimate mail if any sender was missed.
Can fixing SPF break my current email?
If done carelessly, yes — removing a sender that's still active will cause its mail to fail SPF. That's why every mechanism gets checked against your actual active senders before anything is removed.
Do I need to fix SPF if I'm also setting up DKIM and DMARC?
Yes, SPF, DKIM and DMARC work together but each checks something different — a broken SPF record isn't compensated for by having DKIM or DMARC configured correctly.
How long does an SPF fix take to go live?
The DNS change itself is quick, but full propagation can take up to the record's TTL, often up to 24 hours on older records, faster if TTL was already set low.
Please note: the price shown applies to a standard case matching the description above. Every situation is different, and if your request falls outside the normal scope of this service, I will explain this before doing any additional chargeable work. I will never silently turn a small job into an expensive project.
Running into an issue with a service you've already bought, or unsure which one fits your problem? Message me directly on WhatsApp — no ticket system, no bot.