Why SPF, and how to set it up
There is one basic problem with email: anyone sending a message can claim to be anyone. I can send you an email from billgates@microsoft.com, and you have no way of checking whether it came from me or from Bill Gates.
SPF is one of the attempts to fix that, and it is the first of the three records a recipient’s mail server looks at.
A little theory first
SPF is a setting in DNS — on the domain you send from, say microsoft.com. In that domain’s DNS you tell the systems receiving your mail which servers you use to send it.
When a receiving system takes in an email from microsoft.com, it can look up the domain in the sender address, check the SPF record, and confirm that the server the message arrived from is listed there. That also lets it discard mail that did not come from those servers. It is why SPF is effective against phishing: the phisher suddenly needs access to your servers to impersonate you. I can no longer pretend to be Bill Gates unless I can send from one of the servers Microsoft lists in the SPF record on microsoft.com.
Gmail, Outlook and the rest weigh SPF when they receive mail. With a record in place you make their filtering easier, and they repay that by being less aggressive in their spam analysis. It is the reason mail can disappear at Gmail and Outlook when SPF is not set up.
SPF — how
The hard part about SPF is that it requires you to know exactly which servers send mail on your behalf. That used to be easy: one SMTP server for Outlook, one web server for the shop system. Two servers, two IP addresses, done.
Today you send from support systems, email marketing systems, shop systems, payment systems, carriers, review platforms, booking systems and more. Keeping track is genuinely hard.
That is why an SPF record ends with a setting that says how strictly it should be read. A record can look like this:
v=spf1 include:spf.example.com include:spf.ubivox.com -all
The setting is the last part, -all. In plain language, the four versions say:
-all — I have this under control. I send from these servers. If you get
mail from anywhere else, throw it away.
~all — I am testing. I am fairly sure I have it right, and I expect to
move to -all soon, once I am certain every sending server is included. You
should not make decisions based on this record, but I know you might anyway,
so I will switch as quickly as I can.
?all — I do not know exactly which servers send on my behalf. I am
reasonably sure about the ones listed, but mail from elsewhere is probably
fine too.
+all — ANY server may send on my behalf.
Seen from Gmail’s and Outlook’s side, -all and ~all are the only two that
signal you know what you are doing, so they are also the two that do the most
for your chances of reaching the inbox.
Rolling it out
To set SPF up, log in to the domain administration at your hosting provider and add a DNS record — or simply ask them to do it. It should be part of their service.
Include your email marketing provider, your shop provider, your host, your
support software, your review platform and every other system you send mail
from. Start at ~all. When the setup has run for a few weeks and you have
confirmed nothing is missing, switch to -all.
Note that a domain may only have one SPF record. If you already have one, the new sender is added to it rather than given a record of its own — two records invalidate each other, and then the check fails for everything.
You can check your own setup, and see which servers you have included, with our SPF tool.
If you are unsure about your setup, we are happy to take a look. Write to support and we will run a check of the domain together with you.