Authentication
SPF: the guest list for every server that claims to speak for you
One DNS line decides whether a stranger can send mail in your name. Five things to know before you touch it.
SPF is a list, published in your DNS, of the servers allowed to send mail for your domain. When a message arrives, the receiving server checks the sending IP against that list.
Five things to know
- It lives in a TXT record on your domain, starting with
v=spf1. - It checks the envelope sender, which is often not the address the reader sees. That is why SPF alone is not enough.
- Ten DNS lookups at most. Each include and redirect counts, and going over fails the check.
- End with a strict rule.
-allrejects everything not listed;~allonly marks it as suspicious. - Forwarding breaks it. A mailing list or a forwarder sends from its own IP, so the check fails. DKIM covers that case.
A common mistake
- Adding a second SPF record. Two records make the check fail, even if each one looks right.