Updated: 28 September 2026 · Applies to: DNS for mail servers with several IPv4 addresses

SPF is a DNS record that lists the addresses that may send mail for your domain. If you send from several IP addresses of a dedicated server, all of them must be in the record, or receivers may treat your mail as suspicious. This guide shows how to write one SPF record for many addresses without going over SPF's limits.

The basics

  • SPF is a TXT record on the domain that appears in the envelope sender (the Return-Path) and in the HELO name of your server.
  • A domain must have one SPF record. Two records make SPF fail.
  • Mechanisms: ip4: lists addresses or ranges, include: adds the record of another service, a and mx use DNS records, and ~all or -all ends the record.

1. Write the record for your addresses

List a whole block with CIDR notation instead of single addresses:

example.com.   IN  TXT  "v=spf1 ip4:203.0.113.8/29 ip4:198.51.100.0/26 ~all"

This allows the 8 addresses of a /29 and the 64 addresses of a /26. To allow only some addresses:

"v=spf1 ip4:203.0.113.11 ip4:203.0.113.12 ~all"

If you also send through another service (for example Google Workspace), add its include:

"v=spf1 ip4:203.0.113.8/29 include:_spf.google.com ~all"

2. Add it in DNS

  1. Open the DNS settings of the domain. With cPanel use the Zone Editor (How to Add an MX Record in cPanel DNS Zone Editor shows the steps for records).
  2. Add a TXT record with the name of the domain (@) and the value from step 1, without line breaks.
  3. If a record that starts with v=spf1 already exists, edit it; do not add a second one.

3. SPF for the HELO name

Receivers also check SPF for the host name that your server announces (the HELO or EHLO name, see How to make Postfix send from a specific IP address with a matching HELO name?). Add a small record for each mail host name:

mail1.example.com.   IN  TXT  "v=spf1 a -all"

It says that only the address of mail1.example.com may use this name.

4. Check

dig +short TXT example.com
dig +short TXT mail1.example.com

Then send a test message to a Gmail address and look for spf=pass in the "Show original" view.

Limits that matter

  • 10 DNS lookups. Mechanisms such as include, a, mx and redirect cause lookups, and the total may not exceed 10. ip4 and all cause none, which is why listing your addresses with ip4: is the cheapest way.
  • Length. A TXT string is limited to 255 characters; longer values are split into several strings, which most DNS panels do for you. Use CIDR ranges to keep the record short.

~all or -all?

~all (soft fail) tells receivers that mail from other addresses is suspicious. -all (hard fail) asks them to reject it. Start with ~all, and switch to -all when reports and tests show that all your senders are listed. With DMARC in place (How to publish DMARC for your sending domains and tighten the policy safely?) the difference is smaller.

Common mistakes

  • Two SPF records for one domain.
  • Forgetting an address that sends mail (a website server, a helpdesk, a newsletter tool).
  • Using the record on the wrong name: the domain in the MAIL FROM (Return-Path) is the one that is checked, not always the visible From address.
  • Too many include entries.

Frequently asked questions

Do I need SPF if I have DKIM?
Yes. Gmail and Yahoo ask bulk senders for both, and DMARC needs at least one of them to pass and align.

I use a subdomain for newsletters.
Publish the SPF record on that subdomain too.

Need a dedicated server, more IP addresses, or a hand with the setup?

Prefer a hand with the setup? Our engineers can do it for you: Hire an Expert, or use our on-demand server management.

Was this answer helpful? 0 Users Found This Useful (0 Votes)