Email & SMTP
Fix SPF Record
Correct a broken, too-permissive or over-the-limit SPF record so your mail authenticates properly.
The Problem
Your SPF record is rejecting legitimate mail, has too many DNS lookups, or was copy-pasted from somewhere and includes services you don't even use — and every sender you add makes the risk of it silently failing worse.
About this problem
Most broken SPF records aren't broken from day one — they degrade as services are bolted on without anyone removing what's no longer used, until the record either exceeds the 10-lookup limit or ends up authorising senders that have nothing to do with the business any more.
This typically gets fixed after a deliverability problem is traced back to SPF, after a security review flags an overly broad record, or right after adding a new sending tool pushes an already-borderline record over the limit.
What's Included
- Rebuilding the record to include exactly the services that actually send mail for you
- Staying under the 10 DNS lookup limit, flattening includes where needed
- Publishing the corrected TXT record
- Verifying it validates with a real test send
What's NOT Included
- Setting up SPF from nothing when you also need DKIM/DMARC (see the full authentication setup)
- Fixing deliverability problems not caused by SPF
- Ongoing changes every time you add a new sending tool
How It Works
- Audit every mechanism in the current record against services actually in use today.
- Flatten or remove redundant includes to bring the record back under the 10 DNS lookup limit.
- Rebuild the record with only confirmed, active senders, using the correct qualifier (~all vs -all) for your risk tolerance.
- Publish the corrected TXT record and confirm it replaces (not duplicates) the old one.
- Send a real test email through each major sending source and confirm SPF passes in the received headers.
In practice: you buy the service, send over whatever access or details the job needs, I investigate and do the work, and you confirm it's resolved before we call it done.
Frequently Asked Questions
- How do I fix a failing SPF record?
- Identify which mechanism is causing the failure (too many lookups, a missing sender, or a syntax error), then rebuild the record correctly and republish it as a single TXT record at the domain root.
- Why is my SPF record still failing after I fixed it?
- DNS changes take time to propagate, and some mail servers cache the old record for hours — if it's been corrected and still fails after 24-48 hours, there's usually a second, unrelated issue.
- Should I use ~all or -all in my SPF record?
- ~all (softfail) is the safer starting point since it flags unauthorised mail without outright rejecting it; -all (hardfail) is stricter but risks blocking legitimate mail if any sender was missed.
- Can fixing SPF break my current email?
- If done carelessly, yes — removing a sender that's still active will cause its mail to fail SPF. That's why every mechanism gets checked against your actual active senders before anything is removed.
- Do I need to fix SPF if I'm also setting up DKIM and DMARC?
- Yes, SPF, DKIM and DMARC work together but each checks something different — a broken SPF record isn't compensated for by having DKIM or DMARC configured correctly.
- How long does an SPF fix take to go live?
- The DNS change itself is quick, but full propagation can take up to the record's TTL, often up to 24 hours on older records, faster if TTL was already set low.