Skip to main content

Zone records · Intermediate · 10 minutes

SPF Is One TXT Record, and It Has to Live Where Your Zone Does

Only the holder of a name can say who may send from it, and that statement is worth nothing unless it sits in the zone the world is actually querying.

The short answer

SPF is a single TXT record in your own DNS zone naming the servers permitted to send mail using your domain — and it only counts if it sits in the zone your delegated nameservers answer from, not in whichever DNS panel you happened to open. Allow 10 minutes; the work is intermediate rather than difficult.

Three things go wrong, and all three are structural rather than typographical: a second SPF record where the specification allows one, more than ten DNS lookups hidden inside the includes, and a strict -all published before the sender list was finished. Each is dealt with below, in that order.

By the Hosting & Domains team · Reviewed 18 August 2026

Intermediate

Level assumed

10 minutes

Time to allow

5

Stages to work through

24/7

Desk hours

Written for whoever holds the name rather than for whoever runs the server. Registry, registrar, DNS host and mail host are kept apart throughout, because most of the confusion in this subject comes from treating the four as one thing.

Read the part about what goes wrong before you open a zone editor. Nearly every ticket this topic produces arrives from somebody who reached that part second.

Which nameservers actually answer for this name

Before writing anything, establish where the domain is delegated. A WHOIS lookup, or dig NS yourdomain, names the nameservers the world consults. Every other DNS panel you happen to have a login for is decoration: registrars, hosts and CDNs all offer a zone editor, and only one of them is being asked the question.

Where the delegation points at our nameservers, the TXT record goes into the panel's zone editor and the Email Deliverability screen will draft it for you. Where it points at a third party — a CDN, a previous host, a DNS service somebody set up years ago — that is where the record has to be created, and nothing typed here will ever be served.

One SPF record per name, or effectively none

The specification allows exactly one SPF record on a name. Publish a second because a new sending service handed you an include and you did not extend the existing line, and you have voided both. Receiving servers see a permanent error and treat the domain as having published no policy at all.

That is why the failure is so quiet. Each record validates perfectly when checked on its own; the fault exists only in the combination, and the symptom is a slow drift towards spam folders rather than a bounce you could investigate. When a provider gives you an include string, you amend the line already there.

The ten-lookup ceiling, and what eats it

Evaluation is capped at ten DNS lookups. Every include:, a, mx and redirect= spends one, and each include can nest further lookups inside itself that never appear in your record. Four or five mainstream services between them will take you past the limit without any of them behaving badly.

Over the ceiling, evaluation returns permerror and the record is discarded entirely — silently again. Count the lookups with a checker before you publish, remove services that no longer send as you, and flatten stubborn includes into explicit ip4 and ip6 mechanisms if the list genuinely will not fit.

Tightening to -all without stranding a sender

Finish the line on ~all while you are still discovering who sends as you. Softfail marks unauthorised mail without instructing anybody to discard it, which buys room to be wrong. Move to -all once DKIM is signing and a month of DMARC reports shows nothing you cannot account for.

The forgotten sender is always the same sort of thing: an invoicing tool configured two years ago, a booking system, a monitoring alert. None of them fires often enough to be noticed on an ordinary Tuesday, and every one of them stops dead the day a hardfail goes up.

Where SPF ends and alignment begins. SPF authorises the envelope sender, not the address a human reads at the top of the message. Newsletter platforms routinely pass SPF against their own envelope domain while your From: address fails DMARC alignment, so the record is correct, the include is correct, and the report still says fail.

The repair sits on the platform's side: its custom-domain or DKIM configuration, which brings the signing domain into line with yours. SPF cannot fix an alignment problem, and no amount of editing the TXT record will persuade it to try.

Mail landing at an address that carries the domain rather than a free provider

The account these records were published on

Guides written against a hypothetical registrar age badly. These were written at the same zone editor, client area and deliverability screen your own account opens on.

A name renews at the figure you registered it at. No first-year teaser, so no second-year jolt on a domain you have come to depend on.

  • Registry, registrar, DNS host and mail host kept apart
  • Every record shown at the name it belongs on
  • The clock on each change stated as a number
  • A desk that answers at any hour you stall

Why Hosting & Domains

Standard on every plan

Stages, not padding

Each stage is a few minutes of careful clicking, and the parts that genuinely need care are marked as such.

Help on your clock, not ours

Stuck at the zone editor at midnight? The desk answers at any hour, mid-walkthrough included.

The parts the account already handles

Certificates, daily copies and application installs look after themselves, so the page only covers what is genuinely yours to decide.

Registry, registrar, host — kept apart

Each term is defined where it first appears, or linked to the jargon buster. Nothing here uses the four words as though they meant one thing.

Honest about the size of it

Publishing an SPF record is intermediate-level work — allow 10 minutes, with the stages the account already handles marked as such.

The silent failure, named first

The mistake this task actually produces is described before step one, which is how 10 minutes stays 10 minutes.

Quick Start

Order placed to site online

  1. 1

    Confirm where the domain is delegated

    A WHOIS lookup, or dig NS yourdomain, names the nameservers the world actually queries. Every record below goes into that zone and nowhere else, however many other DNS panels you can log into.

  2. 2

    List every envelope your name goes out on

    Hosting mail, the newsletter platform, the CRM, the invoicing run, the monitoring alerts. Anything putting your domain into the envelope belongs on the list, and assembling that list honestly is the real work of the job.

  3. 3

    Compose one v=spf1 line and count its lookups

    Add an include: for each service alongside your host's own mechanism, then total the lookups against the ten-lookup ceiling before you go near the zone editor. Finish the line on ~all for now.

  4. 4

    Publish it as a single TXT record on the apex

    One record on @, and only one. Where a record already exists, edit it. A second SPF record does not extend the first — it voids both, leaving the name worse off than if you had published nothing.

  5. 5

    Validate, then read the headers on a real message

    An SPF checker confirms the syntax and the lookup count. A message sent to an outside mailbox shows spf=pass in Authentication-Results, which is the only confirmation that reflects what receiving servers actually did.

Built In

Fitted to every plan

  • A desk staffed every hour of every day
  • A daily copy of the account, restored from the panel by you
  • The first year of the name included when you order annually
  • WordPress and 400+ other applications in one click
  • WordPress Toolkit, with the updates seen to for you
  • Softaculous bundled, for one-click application installs
  • Plan upgrades applied in place, with no migration and no new server to point at
  • PHP set per name from the panel, not once per account
  • 30 days back on hosting plans, 7 on reseller
  • cPanel, the panel most of the industry already standardised on

Frequently Asked

Questions we field again and again

The mail platform says to add a record — which of my panels does it go in?

Whichever one holds the zone the domain is delegated to. Check the nameservers first: if they are ours, use the panel's zone editor; if they belong to a CDN or a previous DNS provider, the record has to be created there instead. A registrar account with a zone editor you are not delegated to is a common and completely silent dead end.

Do I have to republish SPF after moving registrar?

Not if the nameservers stay where they are. A registrar transfer moves the billing and administrative relationship for the name; it does not move the zone unless you also change the delegation. Where a transfer does bring new nameservers with it, every record — SPF included — has to exist at the new provider before the delegation changes.

Can I transfer in a name I already hold elsewhere?

Yes, and it is routine. Unlock it at the current registrar, ask them for the auth code, and start the transfer from your client area. Whatever registration term remains carries over, DNS keeps resolving throughout, and the standard 60-day lock after a registration or a previous transfer is the only thing that can hold it up.

Are mailboxes on my own name part of a hosting plan?

They are. Every hosting plan includes mailboxes at the name you hold, with webmail, IMAP, POP and SMTP and spam filtering on from the start. There is standalone email hosting too, for a name whose website lives somewhere else entirely.

Keep reading

  • Website Builder

    Build the site on the name you registered, with no code and no separate hosting decision.

  • Domain Names

    Search, register and transfer names — the first year included with an annual plan.

Changing provider? Work through this checklist beforehand.

A straightforward running order for a migration your visitors never spot: which files travel first, how to bring the mail across without dropping a single message, the right moment to repoint DNS, and the two errors that sit behind almost every outage we get called in to fix.

You get the checklist, followed now and then by a note on keeping a site responsive. Unsubscribe whenever you want; the privacy policy covers the rest.

The name is still free. Take it.

Registration, DNS, mailboxes and a certificate on one account — and a desk that answers when a record refuses to resolve.

View Website Builder plans