---
title: "SPF Record Syntax Explained: Understanding SPF Structure, Components, and Best Practices | DMARC Report"
description: "Learn SPF record syntax, mechanisms, qualifiers, and best practices to build accurate SPF records that improve email authentication and deliverability."
image: "https://dmarcreport.com/og/blog/spf-record-syntax-explained-understanding-structure-components-best-practices-guide.png"
canonical: "https://dmarcreport.com/blog/spf-record-syntax-explained-understanding-structure-components-best-practices-guide/"
---

Quick Answer

An SPF record is a DNS TXT record that specifies which mail servers are authorized to send email for your domain. Understanding SPF record syntax, including mechanisms like ip4, ip6, a, mx, and include, helps prevent spoofing, improve email deliverability, and strengthen domain security.

Share 

[ ](https://www.linkedin.com/sharing/share-offsite/?url=undefined%2Fblog%2Fspf-record-syntax-explained-understanding-structure-components-best-practices-guide%2F "Share on LinkedIn") [ ](https://twitter.com/intent/tweet?text=SPF%20Record%20Syntax%20Explained%3A%20Understanding%20SPF%20Structure%2C%20Components%2C%20and%20Best%20Practices&url=undefined%2Fblog%2Fspf-record-syntax-explained-understanding-structure-components-best-practices-guide%2F "Share on X/Twitter") [ ](https://www.facebook.com/sharer/sharer.php?u=undefined%2Fblog%2Fspf-record-syntax-explained-understanding-structure-components-best-practices-guide%2F "Share on Facebook") [ ](https://reddit.com/submit?url=undefined%2Fblog%2Fspf-record-syntax-explained-understanding-structure-components-best-practices-guide%2F&title=SPF%20Record%20Syntax%20Explained%3A%20Understanding%20SPF%20Structure%2C%20Components%2C%20and%20Best%20Practices "Share on Reddit") [ ](mailto:?subject=SPF%20Record%20Syntax%20Explained%3A%20Understanding%20SPF%20Structure%2C%20Components%2C%20and%20Best%20Practices&body=Check out this article: undefined%2Fblog%2Fspf-record-syntax-explained-understanding-structure-components-best-practices-guide%2F "Share via Email") 

![SPF Record Syntax Explained](https://media.mailhop.org/dmarcreport/dmarc-check-5287-1786005227006.jpg) 

## Try Our Free SPF Checker

Instantly analyze any domain's SPF record - check syntax, count DNS lookups, and flag errors.

[ Check SPF Record → ](/tools/spf-checker/) 

Email remains one of the most widely used communication channels for businesses, but it is also a favorite target for cybercriminals. Attackers frequently impersonate trusted domains to deliver [phishing emails](https://thehackernews.com/2026/07/new-ghost-phishing-wave-is-breaking.html), spread malware, or commit [business email compromise (BEC)](https://foleyhoag.com/news-and-insights/blogs/security-privacy-and-the-law/2026/april/business-email-compromises-current-legal-trends-and-key-strategies/). To combat these threats, organizations rely on **email authentication** standards such as Sender Policy Framework (SPF).

SPF allows domain owners to define which mail servers are authorized to send emails on behalf of their domain. When receiving [mail servers](https://www.activecampaign.com/glossary/mail-server) verify an incoming message against an SPF record, they can determine whether the email originated from an approved source. This helps reduce [domain spoofing](https://www.infosecurity-magazine.com/news/infosec2025-email-domains-spoofing/), **strengthens email security**, and supports improved [email deliverability](https://dmarcreport.com/blog/maximize-email-deliverability-with-trusted-email-lookup-verification-apis/).

_In this guide, we’ll explore SPF record syntax, explain every major component, discuss common mechanisms and qualifiers, review practical examples, and share best practices for creating reliable SPF records._

## What Is an SPF Record?

An SPF record is a [DNS TXT record](https://www.cloudflare.com/learning/dns/dns-records/dns-txt-record/) that identifies the mail servers authorized to send email using your domain name. Rather than relying on guesswork, receiving mail servers consult this DNS record whenever they receive an email claiming to originate from your domain.

_If the sending server matches one of the authorized sources listed in the SPF record, the SPF evaluation succeeds._ If it does not, the receiving server may mark the message as suspicious or apply additional filtering based on its own **security policies**.

SPF is one of the three core email authentication technologies, working alongside DKIM (DomainKeys Identified Mail) and [DMARC](https://dmarcreport.com/) (Domain-based Message Authentication, Reporting & Conformance).![Dmarc Lookup 9622](https://media.mailhop.org/dmarcreport/dmarc-lookup-9622-1786005398644.jpg)

## Why SPF Record Syntax Matters

Creating an SPF record isn’t simply a matter of listing **IP addresses**. Every SPF record follows a standardized format that determines how receiving mail servers interpret the policy.

Incorrect syntax may cause:

- SPF validation failures
- Permanent [DNS errors](https://www.logmein.com/blog/what-is-a-dns-error-and-how-to-fix-it)
- Email delivery issues
- Failed [DMARC alignment](https://dmarcreport.com/blog/what-is-dmarc-alignment-and-how-does-it-work/)
- Legitimate messages being treated as suspicious

_Understanding the structure of an SPF record helps administrators avoid configuration mistakes while ensuring every authorized sender is properly included._

## Basic SPF Record Structure

Every [SPF record](https://dmarcreport.com/blog/7-steps-to-verify-spf-record-correctly-using-nslookup-tool/) begins with a version identifier followed by one or more **authorization mechanisms**.

A simple SPF record may look like this:

```
v=spf1 ip4:203.0.113.25 include:_spf.examplemail.com ~all
```

This record tells receiving mail servers:

- The record follows SPF version 1.
- One IPv4 address is authorized.
- Another email provider is also authorized.
- Any sender not matching these rules should receive a **SoftFail result**.

Each portion of the record serves a different purpose.![Dmarc Check 5750](https://media.mailhop.org/dmarcreport/dmarc-check-5750-1786006304443.jpg)

## Breaking Down SPF Record Components

### 1\. Version Identifier

Every SPF record starts with:

`v=spf1`

This declaration tells mail servers that the [TXT record](https://www.digicert.com/blog/what-is-a-txt-record) contains an SPF policy using version 1 of the **SPF specification**.

_Without this identifier, receiving systems will not recognize the record as a valid SPF policy._

## Authorized Sending Sources

After the version tag, the record lists every approved source allowed to send emails for the domain.

These sources can include:

- Individual IP addresses
- IP ranges
- Mail servers
- Third-party email providers
- [Cloud email services](https://www.paubox.com/blog/all-about-cloud-email-services)

Each source is defined using an **SPF mechanism**.

## SPF Mechanisms Explained

Mechanisms are the building blocks of an SPF record. Each mechanism instructs receiving [mail servers](https://www.activecampaign.com/glossary/mail-server) how to verify whether a sender is authorized.

### ip4

The `ip4` mechanism authorizes one or more **IPv4 addresses**.

Example:

```
v=spf1 ip4:198.51.100.10 ~all
```

You can also authorize an entire subnet.

Example:

```
v=spf1 ip4:198.51.100.0/24 ~all
```

This approach is useful when multiple mail servers operate within the same network.

### ip6

Organizations using IPv6 infrastructure can authorize IPv6 addresses with the **`ip6` mechanism**.

Example:

```
v=spf1 ip6:2001:db8::/32 ~all
```

This ensures mail sent from IPv6-enabled infrastructure is evaluated correctly.![Dmarc Report 8066](https://media.mailhop.org/dmarcreport/dmarc-report-8066-1786006269541.jpg)

### a

The `a` mechanism authorizes the IP address associated with a domain’s A or [AAAA DNS record](https://www.cloudflare.com/learning/dns/dns-records/dns-aaaa-record/).

Example:

```
v=spf1 a ~all
```

_When receiving servers evaluate this mechanism, they resolve the domain’s A record and compare it with the sender’s IP address._

### mx

The `mx` mechanism authorizes every server listed in the domain’s MX records.

Example:

```
v=spf1 mx ~all
```

This is helpful when the same mail servers responsible for receiving email also send [outbound messages](https://www.messangi.com/outbound-messages/).

### include

Modern organizations often use multiple cloud email providers.

Instead of manually copying every IP address, the `include` mechanism references another domain’s **SPF policy**.

Example:

```
v=spf1 include:_spf.google.com ~all
```

When this mechanism is encountered, the receiving server evaluates Google’s SPF policy as part of the **authentication process**.

This method simplifies administration while allowing service providers to manage their own infrastructure changes.

![Brad Slavin](https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg) 

[ Brad Slavin ](/authors/brad-slavin/) 

General Manager

Founder and General Manager of DuoCircle. Product strategy and commercial lead for DMARC Report's 2,000+ customer base.

[LinkedIn Profile →](https://www.linkedin.com/in/bradslavin) 

## Take control of your DMARC reports

Turn raw XML into actionable dashboards. Start free - no credit card required.

[Start Free Trial](https://app.dmarcreport.com/signup?plan=free) [Check Your DMARC Record](/tools/dmarc-checker/) 

Scan Your Domain Now

Instantly scan your domain for DKIM, SPF, and DMARC issues

Check My Domain 

Share this article

[ ](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Fdmarcreport.com%2Fblog%2Fspf-record-syntax-explained-understanding-structure-components-best-practices-guide%2F) [ ](https://twitter.com/intent/tweet?text=SPF%20Record%20Syntax%20Explained%3A%20Understanding%20SPF%20Structure%2C%20Components%2C%20and%20Best%20Practices&url=https%3A%2F%2Fdmarcreport.com%2Fblog%2Fspf-record-syntax-explained-understanding-structure-components-best-practices-guide%2F) [ ](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fdmarcreport.com%2Fblog%2Fspf-record-syntax-explained-understanding-structure-components-best-practices-guide%2F) Copy 

Related Articles

- [ ![10 Critical Learnings From Verizon’s 2021 DBIR - A DMARCReport Perspective](https://media.mailhop.org/dmarcreport/images/2022/04/dmarc-alignment-6379.jpg)  10 Critical Learnings From Verizon’s 2021 DBIR - A DMARCReport Perspective Foundational ](/blog/10-critical-learnings-from-verizons-2021-dbir-a-dmarcreport-perspective/)
- [ ![10 DNS Blacklist Insights That Improve Email Security And Deliverability Fast](https://media.mailhop.org/dmarcreport/images/2022/04/dmarc-alignment-6379.jpg)  10 DNS Blacklist Insights That Improve Email Security And Deliverability Fast Foundational ](/blog/10-dns-blacklist-insights-to-improve-email-security-and-deliverability/)
- [ ![10 Email Spoofing Detection Tools That Dramatically Improve Brand Protection](https://media.mailhop.org/dmarcreport/images/2022/04/dmarc-alignment-6379.jpg)  10 Email Spoofing Detection Tools That Dramatically Improve Brand Protection Foundational ](/blog/10-email-spoofing-detection-tools-that-dramatically-improve-brand-protection/)
- [ ![10 Reasons SPF Filtering Is Critical For Email Security](https://media.mailhop.org/dmarcreport/images/2022/04/dmarc-alignment-6379.jpg)  10 Reasons SPF Filtering Is Critical For Email Security Foundational ](/blog/10-reasons-spf-filtering-is-critical-for-email-security/)

## Related Articles

[  Foundational 8m  10 Critical Learnings From Verizon’s 2021 DBIR - A DMARCReport Perspective  Nov 25, 2025 ](/blog/10-critical-learnings-from-verizons-2021-dbir-a-dmarcreport-perspective/)[  Foundational 12m  10 DNS Blacklist Insights That Improve Email Security And Deliverability Fast  Nov 14, 2025 ](/blog/10-dns-blacklist-insights-to-improve-email-security-and-deliverability/)[  Foundational 12m  10 Email Spoofing Detection Tools That Dramatically Improve Brand Protection  Nov 11, 2025 ](/blog/10-email-spoofing-detection-tools-that-dramatically-improve-brand-protection/)[  Foundational 12m  10 Reasons SPF Filtering Is Critical For Email Security  Nov 19, 2025 ](/blog/10-reasons-spf-filtering-is-critical-for-email-security/)

```json
{"@context":"https://schema.org","@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com","logo":{"@type":"ImageObject","url":"https://dmarcreport.com/images/dmarcreport-logo.png"},"description":"DMARC reporting and email authentication management. Monitor aggregate and forensic DMARC reports, analyze authentication results, and enforce DMARC policies across all your domains.","parentOrganization":{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138883901","name":"DuoCircle LLC","url":"https://www.duocircle.com","sameAs":["https://www.wikidata.org/wiki/Q138883901","https://www.crunchbase.com/organization/duocircle-llc","https://www.linkedin.com/company/duocircle","https://github.com/duocircle"],"subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"sameAs":["https://www.wikidata.org/wiki/Q138898167","https://www.linkedin.com/company/duocircle","https://x.com/duocirclellc","https://www.g2.com/products/dmarc-report/reviews","https://github.com/duocircle","https://www.crunchbase.com/organization/duocircle-llc","https://www.trustradius.com/products/duocircle/reviews"],"aggregateRating":{"@type":"AggregateRating","ratingValue":"4.8","reviewCount":"471","bestRating":"5","worstRating":"1","url":"https://www.g2.com/products/dmarc-report/reviews"},"contactPoint":{"@type":"ContactPoint","contactType":"customer support","url":"https://dmarcreport.com/support/"},"knowsAbout":["DMARC","DMARC Reporting","DMARC Aggregate Reports","DMARC Forensic Reports","Sender Policy Framework","DKIM","Email Authentication","Email Security","DNS Management","Email Deliverability"]}
```

```json
{"@context":"https://schema.org","@type":"WebSite","name":"DMARC Report","url":"https://dmarcreport.com","description":"DMARC reporting and email authentication management. Monitor aggregate and forensic DMARC reports, analyze authentication results, and enforce DMARC policies across all your domains.","publisher":{"@type":"Organization","name":"DMARC Report","url":"https://dmarcreport.com","logo":{"@type":"ImageObject","url":"https://dmarcreport.com/images/dmarcreport-logo.png"},"description":"DMARC reporting and email authentication management. Monitor aggregate and forensic DMARC reports, analyze authentication results, and enforce DMARC policies across all your domains.","parentOrganization":{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138883901","name":"DuoCircle LLC","url":"https://www.duocircle.com","sameAs":["https://www.wikidata.org/wiki/Q138883901","https://www.crunchbase.com/organization/duocircle-llc","https://www.linkedin.com/company/duocircle","https://github.com/duocircle"],"subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]}}}
```

```json
[{"@context":"https://schema.org","@type":"BlogPosting","headline":"SPF Record Syntax Explained: Understanding SPF Structure, Components, and Best Practices","description":"Learn SPF record syntax, mechanisms, qualifiers, and best practices to build accurate SPF records that improve email authentication and deliverability.","url":"https://dmarcreport.com/blog/spf-record-syntax-explained-understanding-structure-components-best-practices-guide/","datePublished":"2026-08-06T00:00:00.000Z","dateModified":"2026-08-06T00:00:00.000Z","dateCreated":"2026-08-06T00:00:00.000Z","author":{"@type":"Person","@id":"https://dmarcreport.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://dmarcreport.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin is the founder and General Manager of DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. He founded DuoCircle in 2014 and has led the company's growth to 2,000+ customers across its email security product family. Brad's focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DMARC Report","url":"https://dmarcreport.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com","logo":{"@type":"ImageObject","url":"https://dmarcreport.com/images/dmarcreport-logo.png"},"description":"DMARC reporting and email authentication management. Monitor aggregate and forensic DMARC reports, analyze authentication results, and enforce DMARC policies across all your domains.","parentOrganization":{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138883901","name":"DuoCircle LLC","url":"https://www.duocircle.com","sameAs":["https://www.wikidata.org/wiki/Q138883901","https://www.crunchbase.com/organization/duocircle-llc","https://www.linkedin.com/company/duocircle","https://github.com/duocircle"],"subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"sameAs":["https://www.wikidata.org/wiki/Q138898167","https://www.linkedin.com/company/duocircle","https://x.com/duocirclellc","https://www.g2.com/products/dmarc-report/reviews","https://github.com/duocircle","https://www.crunchbase.com/organization/duocircle-llc","https://www.trustradius.com/products/duocircle/reviews"],"aggregateRating":{"@type":"AggregateRating","ratingValue":"4.8","reviewCount":"471","bestRating":"5","worstRating":"1","url":"https://www.g2.com/products/dmarc-report/reviews"},"contactPoint":{"@type":"ContactPoint","contactType":"customer support","url":"https://dmarcreport.com/support/"},"knowsAbout":["DMARC","DMARC Reporting","DMARC Aggregate Reports","DMARC Forensic Reports","Sender Policy Framework","DKIM","Email Authentication","Email Security","DNS Management","Email Deliverability"]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://dmarcreport.com/blog/spf-record-syntax-explained-understanding-structure-components-best-practices-guide/"},"articleSection":"foundational","keywords":"","image":{"@type":"ImageObject","url":"https://media.mailhop.org/dmarcreport/dmarc-check-5287-1786005227006.jpg","caption":"SPF Record Syntax Explained"},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}}]
```

```json
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://dmarcreport.com/"},{"@type":"ListItem","position":2,"name":"Blog","item":"https://dmarcreport.com/blog/"},{"@type":"ListItem","position":3,"name":"Foundational","item":"https://dmarcreport.com/foundational/"},{"@type":"ListItem","position":4,"name":"SPF Record Syntax Explained: Understanding SPF Structure, Components, and Best Practices","item":"https://dmarcreport.com/blog/spf-record-syntax-explained-understanding-structure-components-best-practices-guide/"}]}
```
