SPF and DMARC Record Builder

Build the two TXT records, with the ten-lookup and 255-character limits checked.

SPF

1 lookups, the limit is 10

Name
example.com
Type
TXT
v=spf1 include:_spf.google.com ~all
DNS lookups, limit 10
1
Characters, limit 255
35

This counts the terms in your own record. Every include: then spends whatever its target's record spends, and that is only knowable by asking DNS, so the real total is this number or higher.

DMARC

Name
_dmarc.example.com
Type
TXT
v=DMARC1; p=none; rua=mailto:[email protected]

46 characters, and the limit is 255.

Used to write the record names, and to notice a report address pointing at another domain. Nothing is looked up.

Who sends mail for this domain

Each box adds the terms shown beside it, which are the ones that provider publishes for its own customers.

A provider missing from this list is one whose include could not be established from its own documentation. Guessing would be worse than leaving it out: a wrong include resolves, matches nothing, and the mail it was meant to cover starts failing while the record still looks right.

Anything else that sends

One domain per line, or separated by spaces or commas. Each one costs a DNS lookup.

Addresses or ranges, one per line. These cost no lookups, which is what makes them the way out of the limit.

What should happen to mail from anywhere else
-all
Says the mail is not yours. Receivers may refuse it outright and most do, which is also what makes a sender you forgot to list disappear without a bounce you will ever see.
~all
Says the mail is probably not yours. It is usually accepted and marked, which is the ending to publish while you are still finding out who sends for you.
?all
Says nothing at all. A receiver treats that sender as though the domain had no SPF record.
DMARC
none
Asks for nothing to be done. With a report address this is how you find out who sends your mail before anything is enforced.
quarantine
Asks receivers to treat failing mail as suspicious, which in practice means the spam folder.
reject
Asks receivers to refuse failing mail at the door. The sender gets a bounce; you get nothing unless you asked for reports.

Worth setting only when subdomains should be treated differently from the domain itself.

Where the daily summaries go. One address is enough; up to four are accepted.

Copies of individual failing messages. Almost no receiver sends these any more.

The share of mail the policy applies to, 0 to 100. Leave it empty for all of it.

Relaxed counts a subdomain as the same organisation; strict requires an exact match. Relaxed is the default and what most domains want.

Built here from what you chose. Nothing is sent anywhere, nothing is stored, and no DNS was asked anything about your domain.

What it cannot tell you: whether the providers you ticked are the ones that actually send your mail. It writes down what you said. Publishing -all with a sender missing from the list means that sender's mail is dropped, quietly, by every receiver that honours it.

It also does not know what your domain publishes now. Adding a second SPF record instead of editing the first is a permanent error in itself, and it fails the same silent way.

To read what a domain publishes today, including whether there is already an SPF record to merge with, use SPF, DKIM and DMARC.