GlossaryAttack surface and pentesting

SPF

Short answer

SPF (Sender Policy Framework) is an email authentication standard that lets a domain owner publish, in a DNS record, which servers are allowed to send email on behalf of that domain. Receiving servers check it to detect messages sent from unauthorised sources.

How it works

The domain owner publishes a TXT record in DNS listing the IP addresses and services authorised to send its email, such as its own mail servers, Microsoft 365 or Google Workspace, and marketing or invoicing platforms. When a message arrives, the receiving server checks whether the sending server is on that list and records the result as a pass or a fail.

Its limits

SPF checks the technical sender address used during delivery (the Return Path), not the From address the recipient sees. An attacker can therefore pass SPF with their own domain while displaying yours. SPF also tends to break when emails are forwarded, and a record cannot require more than 10 DNS lookups, a limit that companies with many sending services can exceed without realising.

SPF, DKIM and DMARC

SPF works best together with DKIM, which signs messages, and DMARC, which ties both checks to the visible From address and tells receivers what to do when they fail. Since 2024, Google and Yahoo require SPF, DKIM and DMARC from organisations that send large volumes of email to their users.

Getting it right

List every legitimate sending service, remove the ones no longer used, end the record with a soft fail (~all) or a hard fail (-all) rather than allowing everything, and monitor DMARC reports to catch services that were missed. A missing or wrong record makes it easier to impersonate the company in phishing and BEC fraud.

Related terms

Keep reading on this topic

External and internal attack surface management, cloud configuration and application security: finding exposures and prioritising them by real risk.

Go to the topic hub