FairSoftware

Free tool

Free SPF Record Generator

Build a valid SPF TXT record for your domain. Tick the services that send email for you, add custom includes or IPs, choose your policy and copy the result.

One per line. Prefix with include:, ip4:, ip6: or a: as needed (or just paste raw entries).

Add this as a single TXT record on your root domain (host '@' or leave blank). Only one v=spf1 record is allowed per domain — merge senders if you already have one.

About this tool

A free SPF record generator for domain owners and IT admins. Tick the email services that send on behalf of your domain — Google Workspace, Microsoft 365, Brevo, Amazon SES, Mailgun and more — add any custom includes or IPs, choose your policy (softfail or hardfail) and copy the resulting SPF TXT string straight into your DNS.

How to use the Free SPF Record Generator

  1. Tick every service that sends email as your domain.
  2. Optionally include your own MX servers and add custom include: or ip4:/ip6: entries.
  3. Pick a policy: ~all (softfail, recommended when starting) or -all (hardfail, once you're confident).
  4. Copy the generated SPF TXT record.
  5. Add it as a single TXT record on your root domain (name: @ or blank).

Frequently asked questions

Where do I put the SPF record?
Add it as a TXT record on your root domain (host '@' or blank) in your DNS provider. Only one SPF (v=spf1) TXT record is allowed per domain — merge multiple senders into one record.
What's the difference between ~all and -all?
~all is softfail: receivers accept the mail but mark it as suspicious. -all is hardfail: receivers should reject unauthorised senders. Start with ~all, move to -all once you're sure every legitimate sender is listed.
Is my data sent anywhere?
No. The record is built entirely in your browser.
Do I still need DKIM and DMARC?
Yes. SPF alone is not enough — pair it with DKIM and DMARC for reliable deliverability and to prevent spoofing.

Related free tools

← Browse all free online tools