Skip to content

Security & DNS

SPF

Sender Policy Framework records that declare exactly which hosts may send mail for a domain, built from a verified inventory of sending sources rather than guesswork.

SPF sending-source inventory and DNS TXT records reviewed on an engineer's console beside a mail relay rack
SYSTEM ACTIVE
SENDER POLICY · SPF

Capabilities

What we implement

  • Sending-source discovery across apps, CRM and marketing tools
  • Record authoring within the ten-lookup limit
  • Flattening and consolidation of nested includes
  • Staged move from softfail to hard fail

Security

How it is hardened

  • Removal of stale include mechanisms and abandoned senders
  • Alignment checked against DMARC before enforcement
  • Change control on the DNS zone holding the record

Architecture

SPF publication path

A record is only as good as the sending inventory behind it. Sources are discovered first, then declared, then enforced.

  1. 01 · Discovery

    Tenant sendersApplication sendersMarketing / CRM toolsLegacy relays

    Every system that sends as the domain is found before the record is written.

  2. 02 · Record design

    include: mechanismsip4 / ip6 entriesLookup budgetFlattening

    The ten-DNS-lookup limit is respected; nested includes are consolidated where a provider allows it.

  3. 03 · Publication

    TXT recordTTL controlSubdomain policy

    Published with a short TTL during change, then raised once behaviour is stable.

  4. 04 · Enforcement

    ~all softfail-all hard failDMARC alignment

    Hard fail only after DMARC reports confirm no legitimate source is missing.

FAQ

SPF questions we are asked

Why is our SPF record failing?
Most often the ten-lookup limit has been exceeded by stacked includes, or a sending platform was added without updating the record. Both show up immediately in DMARC aggregate reports.
Can we have two SPF records?
No. A domain must publish exactly one SPF TXT record; multiple records cause a permanent error and mail starts failing authentication.
Is SPF enough on its own?
No. SPF breaks on forwarding, so DKIM signing and a DMARC policy are needed for the domain to be genuinely protected.

Related

Other security & dns platforms

SPF is referenced to describe engineering capability. All trademarks and product names are the property of their respective owners; no partnership or endorsement is implied.

Ready to scope the work?

Share your environment and objectives. You will get an engineering response covering scope, approach and considerations.