Skip to main content

Walkthrough · Intermediate · 10 minutes

How to Create an SPF Record

How to declare publicly which servers may send email under your domain's name, without the guessing — the steps in order, the snag ahead of time, and the tip our support team repeats daily.

The short answer

One line covers it: declare publicly which servers may send email under your domain's name — a intermediate-level job of roughly 10 minutes.

Below are the precise steps, the classic stumble, and one tip from the support desk. Wherever the platform already does a step for you, the guide says so rather than handing you a machine's chores.

By the Hosting & Domains team · Reviewed 18 August 2026

Intermediate

Skill rating

10 minutes

Time budget

5

Steps in total

24/7

Support on call

No technical background needed. This walkthrough was written for first-timers, proven on our own hardware, and honest about which parts are genuinely tricky rather than merely unfamiliar.

First rule: read the snag section before you start, not afterwards. It was distilled from the tickets of everyone who tried the other order.

How the work divides up

Over the whole job, you will list every legitimate sender, compose the single txt record, publish it once, at the root, audit the lookup count and put it through a validator.

No part of this needs code or a terminal unless the guide says so plainly — and where it does, the exact commands are printed. The step-by-step is below, with the surrounding sections supplying the context that makes it hold.

The error nearly everyone hits

Publishing a second SPF record for a new service instead of amending the one you have. Two SPF records amount to no SPF, and deliverability decays quietly while each record looks perfect on its own.

Forewarned is genuinely forearmed here. This one mistake accounts for most of the frustration the topic ever causes — and it disappears entirely once somebody points it out.

What we tell every customer

Stay on ~all rather than -all until DKIM is live and your monitoring shows the sender list is complete. Strictness is the last step in this process, never the first.

Habits this small are what separate the people who find hosting effortless from the people who find it draining. The same tools on both sides — a different way of working.

What a Hosting & Domains plan spares you

Steps that never deserved your time are taken out: certificates issue and reissue themselves, the installer handles application setup, the daily copy absorbs the what-ifs, and per-site settings live in a panel rather than a configuration file. The guide covers the remainder — the part that is actually about your site.

Should a step still misfire, support answers at any hour with an actual fix rather than a knowledge-base link and a shrug. Half the guides on this site began as repeat patterns in our ticket queue.

Mail landing at an address that carries the domain rather than a free provider

The hosting these steps were tested on

Tutorials written against imaginary hosting go stale fast. Ours are written against the real thing: the same panel, installer and defaults waiting in your account.

The rate you register at is the rate you renew at, so year two costs precisely what year one did — nothing lying in wait on the invoice.

  • Every step checked exactly as published
  • The snag named before it arrives
  • The dull steps taken out of your way
  • People reachable at any hour you stall

Why Hosting & Domains

Standard on every plan

5 steps, nothing padded

Each stage is a few minutes of steady clicking, and the fiddly moments are labelled fiddly.

Help that keeps your hours, not ours

Stuck on step three at midnight? Support answers at any hour, mid-walkthrough included.

The dull parts automated

SSL, backups and installs look after themselves here, leaving the guide to cover only what is genuinely yours.

Jargon never charges you

Every term is defined on the spot or linked to the jargon buster — nothing assumes prior knowledge.

Honest about how big it is

Declare publicly which servers may send email under your domain's name is a intermediate-level job — set aside 10 minutes, with the platform-absorbed steps marked.

The snag, flagged up front

The classic error for this particular task is named before step one, which is how 10 minutes stays 10 minutes.

Quick Start

Order placed to site online

  1. 1

    List every legitimate sender

    Hosting mail, the newsletter platform, the CRM, the invoicing tool: anything sending as you@yourdomain belongs in the record. Putting that list together honestly is the hard part of the whole job.

  2. 2

    Compose the single TXT record

    Begin with v=spf1, add an include: mechanism for each service along with your host's own servers, and finish with ~all. Every service documents the exact include string it expects.

  3. 3

    Publish it once, at the root

    One TXT record on @, and exactly one. A second SPF record does not extend the first; it voids both, leaving you worse off than publishing nothing at all.

  4. 4

    Audit the lookup count

    SPF allows ten DNS lookups, and nested includes from a handful of services get through those faster than you would think. Flatten the includes or cut some out until there is clear room under the limit.

  5. 5

    Put it through a validator

    An SPF checker confirms the syntax and counts the lookups for you. A message sent to a test address then shows the pass sitting in the headers, exactly where receiving servers will read it.

Built In

Fitted to every plan

  • People on the support desk every hour of every day
  • A daily copy, with restores you run yourself from the panel
  • The name's first year included when you order annually
  • WordPress and 400+ further applications installed in one click
  • WordPress Toolkit, with the updates seen to for you
  • Softaculous included for one-click application installs
  • Upgrades applied in place, with no migration when you change plan
  • PHP versions set per site from the control panel
  • Money back within 30 days on hosting plans, 7 on reseller
  • cPanel, which is what most of the industry already runs

Frequently Asked

The questions that come up most

What does SPF actually protect against?

It lets a receiving server check that the machine delivering a message had your domain's authorisation, which prices casual spoofing out of the market and feeds DMARC's verdicts. It is one leg of the SPF, DKIM and DMARC tripod, never a defence on its own.

I added the include but newsletters still fail SPF — why?

The platform is almost certainly sending from its own envelope domain, so SPF passes for them while alignment fails for you. The fix is the platform's custom-domain or DKIM configuration, which brings the signing into line with your domain.

Which control panel do accounts use?

cPanel, the panel the industry standardised on long ago. Every tutorial you find online will match what is on your screen, your backups restore onto any other cPanel host, and the skills stay useful for life. Plesk and DirectAdmin are available on particular plans if you prefer either.

How quickly can a site be live?

Quickly — minutes rather than days. The account opens the moment payment clears, the domain (free for the first year on annual plans) attaches straight away, and the one-click installer has WordPress or any of 240+ applications running before your coffee cools. Site already somewhere else? Send the details and we move it free, normally within a day.

Keep reading

  • How to Take Payments Online

    Collect money safely without dragging card data onto your own server — beginner level, about an hour.

  • How to Create a Contact Form

    A form visitors actually complete, sending mail that actually arrives — beginner level, about 30 minutes.

  • MX Record (Glossary)

    A single term without the jargon: what it means, why it counts, and where it catches people out.

  • Website Builder

    Drag, drop, publish — a no-code builder on genuinely quick hosting.

  • Domain Names

    Find, register and transfer names — year one free with annual hosting.

Changing hosts? Run through our checklist first.

A plain order of work for a move nobody visiting will notice: which files go over first, how to carry the mail across without losing a message, when exactly to repoint DNS, and the two mistakes behind nearly every outage we are asked to rescue.

What arrives is the checklist, and then the occasional note on keeping a site quick. Leave whenever you like; the privacy policy covers the rest.

The name is waiting.

Every plan carries the essentials other hosts bill as extras — and support that answers.

View Website Builder plans