{"id":45027,"date":"2022-11-26T21:11:18","date_gmt":"2022-11-26T21:11:18","guid":{"rendered":"https:\/\/www.arimetrics.com\/glosario-digital\/spf"},"modified":"2026-10-01T07:07:30","modified_gmt":"2026-10-01T07:07:30","slug":"spf","status":"publish","type":"encyclopedia","link":"https:\/\/www.arimetrics.com\/en\/digital-glossary\/spf","title":{"rendered":"SPF"},"content":{"rendered":"<p><img decoding=\"async\" class=\"boxpad alignright wp-image-45116 size-full\" src=\"https:\/\/www.arimetrics.com\/wp-content\/uploads\/2022\/12\/spf.jpg\" alt=\"SPF\" width=\"300\" height=\"300\" srcset=\"https:\/\/www.arimetrics.com\/wp-content\/uploads\/2022\/12\/spf.jpg 300w, https:\/\/www.arimetrics.com\/wp-content\/uploads\/2022\/12\/spf-150x150.jpg 150w\" sizes=\"(max-width: 300px) 100vw, 300px\" \/><strong>Definition:<\/strong><\/p>\n<p><strong>SPF<\/strong>, short for Sender Policy Framework, is an email authentication protocol that lets a domain publish which servers are authorised to send messages on its behalf. The policy is stored as a TXT record in DNS, and the receiving server compares it with the IP address delivering the message.<\/p>\n<p>The check applies to the domain used in the SMTP envelope, normally the MAIL FROM domain, or to the HELO identity when appropriate. On its own, it does not authenticate the visible From address, the message content, or a person&#8217;s identity. SPF is therefore a <strong>technical signal<\/strong> that receivers combine with other checks and their own delivery rules.<\/p>\n\n<h2>How SPF validation works<\/h2>\n<p>When a platform sends an email, it opens an SMTP connection to the recipient&#8217;s server. The receiver identifies the source IP and queries <a href=\"https:\/\/www.arimetrics.com\/en\/digital-glossary\/dns\">DNS<\/a> for the policy of the domain declared in the envelope. The evaluation determines whether that combination of domain and IP is <strong>authorised<\/strong>.<\/p>\n<p>The result does not universally instruct the receiver to accept or reject the message. A provider may feed it into filtering systems, record it in the Authentication-Results header, or combine it with reputation, content, and other signals. Its <strong>delivery rules<\/strong> also matter. A valid result can support <a href=\"https:\/\/www.arimetrics.com\/en\/digital-glossary\/deliverability\">deliverability<\/a>, but it does not guarantee inbox placement.<\/p>\n<p>SPF does not always survive transport unchanged. Forwarding may cause the message to arrive from an IP address that the original domain did not authorise. This behaviour is one reason why <strong>SPF alone<\/strong> cannot represent the entire email authentication process.<\/p>\n<h2>Syntax of an SPF record<\/h2>\n<p>The policy is published in a single TXT record beginning with <strong>v=spf1<\/strong>. It then contains mechanisms and modifiers describing permitted sources and the result to apply when none of them matches.<\/p>\n<p>The most common components serve different purposes:<\/p>\n<ul>\n<li><strong>ip4 and ip6:<\/strong> Authorise specific addresses or network ranges.<\/li>\n<li><strong>a and mx:<\/strong> Use addresses resolved from the A, AAAA, or MX records of the specified domain.<\/li>\n<li><strong>include:<\/strong> Evaluates another domain&#8217;s policy, which is common when sending is delegated to an external platform.<\/li>\n<li><strong>all:<\/strong> Matches every remaining source and usually closes the policy with a qualifier.<\/li>\n<li><strong>redirect:<\/strong> Replaces the evaluation with another domain&#8217;s policy when no previous mechanism has matched.<\/li>\n<li><strong>Qualifiers:<\/strong> The prefixes +, -, ~, and ? express pass, fail, softfail, and neutral.<\/li>\n<\/ul>\n<p>Mechanisms that trigger DNS queries are subject to an operational limit of ten during an evaluation, as specified in the <a href=\"https:\/\/www.rfc-editor.org\/info\/rfc7208\/\" target=\"_blank\" rel=\"noopener\">SPF technical specification<\/a>. Exceeding it can produce a permanent error, so adding services through include without reviewing the policy creates a <strong>fragile configuration<\/strong>.<\/p>\n<h2>Results of an SPF check<\/h2>\n<p>The evaluation does not return only approved or rejected. It produces several <strong>standard results<\/strong> that describe the match and the state of the query:<\/p>\n<ul>\n<li><strong>Pass:<\/strong> The IP address is authorised by the published policy.<\/li>\n<li><strong>Fail:<\/strong> The policy states that the IP address should not use the domain.<\/li>\n<li><strong>Softfail:<\/strong> The IP is probably not authorised, but the domain applies a less strict signal.<\/li>\n<li><strong>Neutral:<\/strong> The policy makes no assertion about whether the source is authorised.<\/li>\n<li><strong>None:<\/strong> No applicable SPF policy exists.<\/li>\n<li><strong>Temperror:<\/strong> A temporary problem, such as a DNS failure, prevents completion of the check.<\/li>\n<li><strong>Permerror:<\/strong> The policy contains a permanent syntax, structure, or processing error.<\/li>\n<\/ul>\n<p>The final action depends on the receiver and its policy. Even a pass does not prove that a message is legitimate: an authorised account may be compromised, and a malicious domain can publish SPF correctly. For the same reason, SPF is not a complete <strong>spam filter<\/strong> or comprehensive protection against <a href=\"https:\/\/www.arimetrics.com\/en\/digital-glossary\/phishing\">phishing<\/a>.<\/p>\n<h2>Complementary email authentication<\/h2>\n<p>SPF checks the sending path associated with the SMTP envelope. DKIM instead adds a cryptographic signature linked to a domain and can reveal certain changes to the message. DMARC uses SPF and DKIM results and requires at least one to align with the domain visible in From before applying a <strong>domain policy<\/strong>.<\/p>\n<p>This combination addresses limitations that SPF cannot solve by itself. DMARC alignment connects authentication with the <strong>visible identity<\/strong>, while DKIM may survive some forwarding when the signed message remains unchanged. No single mechanism classifies all <a href=\"https:\/\/www.arimetrics.com\/en\/digital-glossary\/spam\">spam<\/a> or proves the sender&#8217;s intention.<\/p>\n<h2>Maintaining an SPF policy<\/h2>\n<p>A reliable policy must represent every system that sends mail for the domain: internal infrastructure, transactional providers, support tools, and <a href=\"https:\/\/www.arimetrics.com\/en\/digital-glossary\/email-marketing\">email marketing<\/a> platforms. The central task is to keep an <strong>updated inventory<\/strong> and remove authorisations that are no longer used.<\/p>\n<p>Management can include these checks:<\/p>\n<ol>\n<li><strong>Unify the record:<\/strong> Publish one SPF policy per domain name and combine the required sources within it.<\/li>\n<li><strong>Control lookups:<\/strong> Review include, a, mx, exists, and redirect so the processing limit is not exceeded.<\/li>\n<li><strong>Validate services:<\/strong> Confirm that each platform uses the expected envelope domain and provides current instructions.<\/li>\n<li><strong>Test changes:<\/strong> Check syntax, results, and legitimate mail flows before applying a restrictive policy.<\/li>\n<li><strong>Review incidents:<\/strong> Analyse failures, forwarding, and provider changes alongside available authentication reports.<\/li>\n<\/ol>\n<p>An overly permissive policy authorises more infrastructure than necessary; one that is too strict may disrupt legitimate mail. The objective is to maintain <strong>precise authorisation<\/strong> coordinated with DKIM, DMARC, and the actual configuration of every email channel.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Definition: SPF, short for Sender Policy Framework, is an email authentication protocol that lets a domain publish which servers are authorised to send messages on its behalf. The policy is stored as a TXT record in DNS, and the receiving server compares it with the IP address delivering the message. The check applies to the [&hellip;]<\/p>\n","protected":false},"author":6,"featured_media":0,"template":"","encyclopedia-tag":[1373],"class_list":["post-45027","encyclopedia","type-encyclopedia","status-publish","hentry","encyclopedia-tag-email-deliverability"],"_links":{"self":[{"href":"https:\/\/www.arimetrics.com\/en\/wp-json\/wp\/v2\/encyclopedia\/45027","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.arimetrics.com\/en\/wp-json\/wp\/v2\/encyclopedia"}],"about":[{"href":"https:\/\/www.arimetrics.com\/en\/wp-json\/wp\/v2\/types\/encyclopedia"}],"author":[{"embeddable":true,"href":"https:\/\/www.arimetrics.com\/en\/wp-json\/wp\/v2\/users\/6"}],"wp:attachment":[{"href":"https:\/\/www.arimetrics.com\/en\/wp-json\/wp\/v2\/media?parent=45027"}],"wp:term":[{"taxonomy":"encyclopedia-tag","embeddable":true,"href":"https:\/\/www.arimetrics.com\/en\/wp-json\/wp\/v2\/encyclopedia-tag?post=45027"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}