Get started
Email deliverability

SPF records: how to write one, merge two, and stay under 10 lookups

SPF is a TXT record listing the servers allowed to send email as your domain. A domain can have only one. The most common SPF mistake is having two, which makes SPF fail completely.

What's in an SPF record

v=spf1 mx a:mail.syncgaze.in ip4:157.173.222.40 ~all
  • v=spf1: marks the record as SPF. It must come first.
  • mx, a:host, ip4:…, include:domain: the senders you allow.
  • ~all: everything else is a "soft fail" (usually spam). -all means reject. Never use +all, which lets anyone send as you.

Merging two SPF records

If your website host or billing tool also sends mail as you, put every sender into one record.

Before (broken — two records): v=spf1 include:_spf.mail.hostinger.com ~all v=spf1 mx a:mail.syncgaze.in ip4:157.173.222.40 ~all After (one record): v=spf1 mx a:mail.syncgaze.in ip4:157.173.222.40 include:_spf.mail.hostinger.com ~all

Keep the old provider's include: only if it still sends mail for you. If you've moved away from it completely, drop it.

The 10-lookup limit

Each include:, a, mx and redirect costs one DNS lookup, and include: can hide more lookups inside. More than 10 lookups in total gives a PermError, and receivers treat it as no SPF at all. To stay under the limit:

  • Remove includes for services you no longer use.
  • Use ip4: for fixed servers, which cost no lookup.
  • Send newsletters from a subdomain such as news.yourcompany.com, which has its own SPF record.

Check your SPF now. It flags missing, duplicate and loose (+all) records.

Verify and test

  1. Wait 5–30 minutes after saving. Most changes show up within minutes, but some take up to a few hours.
  2. Go back to dashboard.syncgaze.in → Domains and click Verify. Each record turns green when SyncGaze can see it.
  3. Run a free check on mail.syncgaze.in/check. It reads your MX, SPF, DKIM and DMARC records and explains anything still missing.
  4. Send a test email to a Gmail address and open Show original. It should show SPF: PASS, DKIM: PASS and DMARC: PASS.
{# Help Assistant is self-injected by static/help/assistant.js (loaded in base.html). Nothing to render here — kept so the base.html include stays valid. #}