SPF record settings
Only one SPF record is to be added to the domain DNS zone. It defines which IP addresses are authorized to send email on behalf of a specific domain.
By configuring an SPF record, you can tell recipient servers which IP addresses are authorized to send email using your domain name as the sender. This setting helps you increase your security and protect yourself from email scams.
Setting a correct SPF record reduces the likelihood that someone can use your domain to send spam or phishing emails and increases the chances that your message will not be marked as unwanted. Setting an SPF record is a very simple configuration to perform, has no additional cost, and has no impact on performance.
It is strongly recommended to set an SPF record for every active domain on EhloMail.
Set an SPF record
To set the SPF record on your domain, you must access the DNS management panel of the provider where you registered the domain and add in the existing record (if it exists) include:_spf.mail.ls. It should look like this:
| Record Type | Value |
|---|---|
| TXT | v=spf1 a mx include:_spf.mail.ls -all |
The setting shown above also authorizes email sending by the server hosting your website.
The SPF record check is performed by the server that receives the email. Once the record changes are saved, it may take up to 24 hours for the DNS change to become fully operational, depending on the record TTL value.
Advanced settings to enable SPF records from other providers
If emails with your domain as the sender are also sent from other providers, you must also add their SPF settings by adding their “include” entries as shown in the following example:
| Record Type | Value |
|---|---|
| TXT | v=spf1 a mx include:_spf.mail.ls include:_spf.example.com -all |
You can also add specific IP addresses to your domain SPF record:
| Record Type | Value |
|---|---|
| TXT | v=spf1 a mx include:_spf.mail.ls ip4:1.2.3.4/32 -all |
Make sure you publish only one TXT record that includes all the necessary SPF entries
all mechanism
The all mechanism in an SPF record acts as a catch-all rule that tells the server that checks the SPF record how to handle the request from an IP address that is not explicitly resolved from the other defined mechanisms.
It can be combined with:
| Qualifier | Value | Action taken by the server that checks the record |
|---|---|---|
| - | -all | reject messages from your domain if they do not come from one of the IPs specified in the SPF record |
| ~ | ~all | accept, but mark suspicious, messages from your domain if they do not come from one of the IPs specified in the SPF record |
The following qualifiers are valid but don't make sense to use:
| Qualifier | Value | Action taken by the server that checks the record |
|---|---|---|
| ? | ?all | accept, as if the domain didn't have an SPF record, messages from your domain if they do not come from one of the IPs specified in the SPF record |
| + | +all | accept messages as if all the IP addresses are listed in your SPF record |