How it works
The domain owner publishes a TXT record in DNS listing the IP addresses and services authorised to send its email, such as its own mail servers, Microsoft 365 or Google Workspace, and marketing or invoicing platforms. When a message arrives, the receiving server checks whether the sending server is on that list and records the result as a pass or a fail.
Its limits
SPF checks the technical sender address used during delivery (the Return Path), not the From address the recipient sees. An attacker can therefore pass SPF with their own domain while displaying yours. SPF also tends to break when emails are forwarded, and a record cannot require more than 10 DNS lookups, a limit that companies with many sending services can exceed without realising.
SPF, DKIM and DMARC
SPF works best together with DKIM, which signs messages, and DMARC, which ties both checks to the visible From address and tells receivers what to do when they fail. Since 2024, Google and Yahoo require SPF, DKIM and DMARC from organisations that send large volumes of email to their users.
Getting it right
List every legitimate sending service, remove the ones no longer used, end the record with a soft fail (~all) or a hard fail (-all) rather than allowing everything, and monitor DMARC reports to catch services that were missed. A missing or wrong record makes it easier to impersonate the company in phishing and BEC fraud.




