The records
Each include is a sender. Add the include your other services document, such as your CRM, helpdesk or invoicing tool.
Microsoft 365: v=spf1 include:spf.protection.outlook.com -all
Google Workspace: v=spf1 include:_spf.google.com ~all
Both, plus a newsletter tool:
v=spf1 include:spf.protection.outlook.com include:_spf.google.com include:servers.mcsv.net ~allCommon mistakes
- Two SPF records on the same domain. There must be exactly one TXT record starting with v=spf1; merge them
- More than 10 DNS lookups. Each include, a, mx and redirect counts, including nested ones. Past 10, SPF returns a permanent error
- Using +all, which lets anyone send as you
- Forgetting a sender, so its mail fails SPF and, once DMARC is enforced, gets rejected
- Leaving old includes for services you no longer use
~all or -all?
~all (soft fail) asks receivers to accept but treat failures with suspicion. -all (hard fail) says anything not listed isn't you. With DMARC enforced, the DMARC policy decides what happens, so either works; -all is the stricter signal once you're confident the list is complete.
Doing it with TenantWard
TenantWard reads your SPF, counts lookups, spots duplicates and proposes a corrected record. With your DNS host connected it publishes the change, keeps the previous value and can undo it.
Questions
- What is the SPF record for Microsoft 365?
- v=spf1 include:spf.protection.outlook.com -all, plus an include for any other service that sends email as your domain.
- What is the SPF record for Google Workspace?
- v=spf1 include:_spf.google.com ~all, plus an include for any other service that sends email as your domain.
See where your company stands
Check a domain for free, then connect Microsoft 365 or Google Workspace for the full checkup. Every new workspace gets a 7-day trial, no card needed.