Updated: 28 September 2026 · Applies to: Google Workspace with any DNS host

An SPF record is a line of text in your domain's DNS that lists the servers allowed to send email for your domain. Receiving mail servers check it, and mail from unlisted servers is more likely to land in spam. For Google Workspace the record is short. You set it in DNS only; nothing has to be changed in the Google Admin console.

The record for Google Workspace

  • Type: TXT
  • Name / Host: @ (the domain itself)
  • Value: v=spf1 include:_spf.google.com ~all

The ~all at the end (soft fail) tells receivers to treat mail from any other server as suspicious.

Steps

  1. Log in where your domain's DNS is managed. For your Ucartz cPanel hosting see How to add Google Workspace DNS records (MX, SPF, DKIM, DMARC) in cPanel?.
  2. Look for an existing TXT record that starts with v=spf1. A domain must have only one SPF record. If one exists, do not add a second: edit it (see the next section).
  3. If none exists, add the TXT record from the list above.
  4. Save. Changes can take up to 48 hours to be visible everywhere; usually it is much faster.
  5. Check it: dig +short TXT example.com should show the line that begins with v=spf1.

You also send mail from other places

Add each additional sender to the same record instead of creating another one. Examples:

v=spf1 include:_spf.google.com ip4:203.0.113.10 ~all

Here 203.0.113.10 stands for the IP address of your own server that sends contact-form mails or newsletters. A newsletter service gives you its own include: value; add it before ~all. Keep the record short: SPF allows at most 10 lookups in total.

Check that it works

  1. Send a mail from a Google Workspace address to a personal account at another provider.
  2. Open the message and use "Show original" (in Gmail) or the message source. Look for SPF: PASS.

Common mistakes

  • Two SPF records. Receivers then ignore both. Merge them into one line.
  • Wrong Name. The record belongs to the domain itself (@), not to www or mail.
  • Quotes or line breaks inside the value that your DNS panel added. The value must be a single line.
  • The website or server sends mail that is not in the record. Add its IP address as shown above.

Next

SPF alone is not enough for good delivery. Add DKIM (How to set up DKIM for Google Workspace?) and DMARC (How to set up DMARC for Google Workspace?).

Frequently asked questions

Should I use -all instead of ~all?
Google's example uses ~all. It is the safer choice while you are still discovering all the systems that send mail for your domain.

Do I need SPF if I only receive mail?
SPF is about sending. It matters as soon as anyone sends mail from your domain, including replies.

Official documentation: Google Workspace Admin help: set up SPF.

Need Google Workspace or help with the DNS records?

  • Google Workspace: plans for your business email, calendar, Drive and Meet, available in the Ucartz store.

Prefer a hand with the setup? Our engineers can do it for you: Hire an Expert, or use our on-demand server management.

Was this answer helpful? 0 Users Found This Useful (0 Votes)