Skip to content

Email-domain security

What is SPF?

The domain's SPF record: whether there is exactly one, whether it parses, whether it ends in a policy that rejects other senders, and whether evaluating it stays within 10 DNS lookups.

Part of the External Security Check. Free during the preview.

What it checks

The domain's SPF record: whether there is exactly one, whether it parses, whether it ends in a policy that rejects other senders, and whether evaluating it stays within 10 DNS lookups.

A pass means: An SPF record lists the servers allowed to send mail for the domain.

Possible findings

No SPF record

Severity: MediumConfidence: ConfirmedKind: Security issue

What we found

The domain does not publish an SPF record.

Why it matters

Without SPF, receiving mail servers cannot tell which servers may send mail for your domain, making it easier to send convincing phishing as you.

How to fix it

Publish a TXT record starting v=spf1 that lists the services that send your mail and ends in -all or ~all, for example v=spf1 include:_spf.google.com -all.

More than one SPF record

Severity: MediumConfidence: ConfirmedKind: Security issue

What we found

The domain publishes more than one SPF record.

Why it matters

The SPF standard treats multiple records as an error, so receivers ignore SPF for your domain entirely.

How to fix it

Merge the records into a single v=spf1 TXT record.

SPF allows any server to send

Severity: HighConfidence: ConfirmedKind: Security issue

What we found

The SPF record ends in +all or ?all, so it does not reject any sender.

Why it matters

An SPF record that allows everyone gives no protection against spoofing, and +all actively vouches for forged mail.

How to fix it

End the record with -all (or ~all while testing) after listing your real sending services.

SPF needs too many DNS lookups

Severity: MediumConfidence: High confidenceKind: Security issue

What we found

Evaluating the SPF record needs more than the 10 DNS lookups the standard allows.

Why it matters

Receivers stop evaluating after 10 lookups and treat the result as an error, so legitimate mail may fail SPF.

How to fix it

Remove unused includes, replace a/mx/ptr mechanisms with IP ranges where stable, or use your provider's flattened include.

SPF record has errors

Severity: MediumConfidence: High confidenceKind: Security issue

What we found

The SPF record contains syntax that receivers will reject.

Why it matters

Receivers treat a malformed record as an error, which usually means no SPF protection.

How to fix it

Correct the record. Each term must be a valid mechanism (ip4:, ip6:, include:, a, mx, exists:) or modifier (redirect=, exp=).

References