SPF Configuration Settings & Setup
Understand your SPF configuration settings and set up SPF record delegation to enable management through Sendmarc.
To enable management of your SPF record, you'll first need to add your domain to Sendmarc. Once your domain is added you can set up DNS delegation for your SPF record. This means that your SPF record in your DNS is pointed to our servers, which contain the settings of your SPF record.
Setup & Verify SPF Delegation
If this is your first time editing your domain, it is important to validate the imported settings against your existing DNS records to ensure that no records were missed, as Sendmarc will only import valid records. You'll need to manually add the authorized senders and settings that failed to import. Be sure to do so before enabling DNS delegation.
SPF management is only available for specific account plans.
Steps to follow
- Navigate to Domains in the left navigation bar.
- Click on the Pencil icon to edit a domain from the list, or click the domain name in the list.
- On the Domain Settings page, click on the SPF tab, confirm the correct settings have been imported/applied, and make necessary adjustments where needed.
- The RAW SPF Record is displayed at the bottom of the settings page; this is the hosted record that Sendmarc compiles based on the settings you have set in the platform.
- Once you're happy with your settings, go to the SPF Setup Instructions section to reveal the DNS record required to enable SPF management for your domain.
- The SPF Setup Instructions page will show you a step-by-step guide on the changes required to your DNS records to enable delegation. The page will contain:
- New TXT Record – This is the new DNS record to enable delegation
- TXT Record with include (Not Recommended) – Use this record to allow partial verification. This method does not allow for full verification and complete SPF record delegation, which means some changes to settings will not take effect. Recommended for DNS providers that do not support redirects.
- Verification Status – Indicates the various states of verification with the date and time that the last validation occurred.
- Add the TXT record to your DNS to enable delegation. The process of updating your DNS may differ depending on your hosting provider. Visit the Service Provider Section for more information.
- Click Verify to validate your newly added DNS record. It may take some time for the record to reflect, but Sendmarc will continue to attempt verification in the background.
- Once your setup has been fully verified, you've successfully delegated the management of your SPF record to the Sendmarc platform. This will be indicated by a green tick.
Various States of Verification
- Verified – Matching TXT record found and SPF delegation is enabled
- Not Verified – No matching TXT record found
Sendmarc needs to verify whether your SPF record contains the valid delegated record before you can start managing your SPF settings through our platform. The record inside of your DNS needs to be the exact record that was provided in the setup instructions. If correct, your SPF setup will be set to "verified" and your SPF settings can be managed through our platform.
If you have just created a new domain and the verification is failing, please allow the full Time To Live (TTL) of the domain to lapse its configured period and try validation again.
SPF Configuration Settings
Understand the various settings available for your SPF record. These settings will only take effect if DNS delegation has been implemented and verified. Follow the setup instructions above.
Configuring Authorized Senders
The Authorized Senders in the list are those you have configured as legitimate senders. This list is generated in one of three ways:
- Automatically imported during domain creation
- Manual Import (If your SPF record has not yet been verified/delegated you can choose to re-import the existing SPF record and Sendmarc's Smart Import Technology will import it for you. It will only import the valid records and Authorized Senders not already on the list.)
- Manually added and configured by you
You can modify each of your Authorized Senders by clicking on the Pencil icon to edit the directive. This will allow you to verify settings and update the directive accordingly. To change the order of the directives, use the 3 bars icon to drag each directive up or down into the correct place.
To add a new Authorized Sender or Directive click Add New SPF Directive.
For each of the records you can specify:
- Type (Include, Exists, A, MX, ip4, ip6)
- Qualifier
- "-" fail
- "~" soft fail
- "?" neutral (Not Recommended)
- "+" pass (Not Recommended)
- Host / Address / Macro Value (Changes based on mechanism selected)
- Description – Used for notes
SPF Flattening
SPF Flattening is disabled by default. When enabled, it will reduce all your SPF includes (Authorized Senders) down to the IP level when the lookup limit is reached. Learn more about SPF Optimization
All Term – Default Qualifier
This option allows you to choose how you would like senders not listed as an Authorized Sender to be treated, also known as the "Termination Mechanism". The options are:
- "-" fail – Fail unauthorized senders
- "~" soft fail – Soft fail unauthorized senders
- "?" neutral – Neutral stance on unauthorized senders (Not Recommended)
- "+" pass – Allow unauthorized senders (Not Recommended)
Need Help?
[email protected] is standing by to assist!
Looking for how to configure DKIM in Sendmarc?
Find out how to add DKIM keys to your Sendmarc-managed domain here.