EMZETT.
Login

SPF

In short: SPF (Sender Policy Framework) is a DNS record that defines which servers may send email for a domain.

In more detail: Receiving mail servers check whether the sending IP address is listed in the SPF record of the sender domain. This makes spoofing, that is forged senders, harder. SPF is a TXT record in the DNS zone.

In Depth

Example:

example.com.  TXT  "v=spf1 ip4:203.0.113.5 include:_spf.mailprovider.com -all"
  • v=spf1 marks SPF.
  • ip4: allows one address, include: adopts the rules of a provider (e.g. the email service).
  • The ending defines what happens to everything else: -all (reject), ~all (mark as suspicious, “softfail”).

Limits

  • The technical sender (envelope) is checked, not the visible “From:” address.
  • SPF can fail with forwarded mail.
  • At most 10 DNS lookups per check are allowed.
  • SPF alone is not enough. It is combined with DKIM (a signature of the message) and DMARC (a rule for what happens on failure). Together they protect against phishing in the name of your own domain.

See also: DNS records, domain, name server