LochStudios  /  Help Centre  /  Email Deliverability  /  SPF Records Explained and How to Set One Up

SPF Records Explained and How to Set One Up

What an SPF record is, how to publish one TXT on AtlasDNS or in cPanel, and how to merge senders for shared hosting and LochStudios Mail.

Updated

SPF (Sender Policy Framework) is a TXT record on your domain. It lists which servers may send mail as that name. When a message claims to be from you, the receiving inbox looks up the record and checks the sending IP. If the IP is not listed, the message is more likely to land in spam.

We publish this with you. Unsure which product or DNS mode you are on? Open a support ticket and we will set the record.

SPF is one of three authentication records. Also see DKIM explained and DMARC explained.

Which mail product

The string must list the product that actually sends the mail.

  • Shared hosting (mailboxes you create in cPanel): let cPanel Email Deliverability write the SPF, or copy the value it shows. See Create an email account.
  • LochStudios Mail (hosted business email): copy the SPF value from the mail service in the portal. Open that service and use Log in to WebMail for the inbox. See What is Axigen webmail and how to sign in.
  • A VPS you manage: add that server's IPv4 from the portal (ip4:). Credentials and the console are on the server in the portal. Only do this if that VPS is the host that sends the mail.
  • Another sending system (a newsletter tool, a CRM, or mail that is not hosted here): they give you an include: or an IP. Merge that into the same SPF string. Do not add a second SPF record.

Do not mix those paths. A cPanel SPF will not authorise LochStudios Mail, and the other way around, unless you merge both into one string.

Where the TXT record goes

SPF is a TXT record on the root name (@ / yourdomain.com). It is not a separate record type. AtlasDNS is the default. Do not send the domain to a third-party DNS host.

  1. Sign in at /portal.
  2. Open Domains, then the domain, then DNS.
  • AtlasDNS (the usual case): add or edit the TXT on that page. When the domain uses AtlasDNS, the nameservers are:
ns1.atlasdns.net.au
ns2.atlasdns.net.au
ns3.atlasdns.net.au
  • cPanel Hosting DNS mode (the domain is paired with a shared hosting service): the portal says records are managed from the hosting control panel. Open the hosting service, click Log in to cPanel, and use Email Deliverability (it can write the record) or the Zone Editor.

Unsure which mode you are on? Open a support ticket.

Why SPF matters

Receiving inboxes use SPF to decide whether the sending server is allowed to use your domain.

  • Spoofed mail from a random IP fails the check instead of looking like it came from you.
  • Legitimate mail is more likely to reach the inbox. See Why your emails go to spam.
  • DMARC can only pass on SPF when the domain that passed matches the domain in the From address (alignment).
  • Large inboxes expect a published SPF record from domains that send mail.

SPF lists who may send. DKIM signs the message. You want both.

How a check works

  1. You publish one TXT on the sending domain, starting with v=spf1.
  2. When a message is handed off, the receiving server notes the sending IP and the envelope sender (the Return-Path / MAIL FROM domain, which is not always the visible From address).
  3. It looks up the TXT for that envelope domain.
  4. It walks the mechanisms (ip4, include, a, mx, and so on) until one matches or it hits all.
  5. The result is pass, fail, or soft fail, depending on how you ended the record.

If two different v=spf1 TXT values exist on the same name, receivers treat SPF as broken. Edit the existing row. Do not add another.

Enable SPF on shared hosting

Open cPanel from the portal. Do not guess a hostname.

  1. Sign in at /portal, open the hosting service, and click Log in to cPanel.
  2. In the Email section, open Email Deliverability.
  3. Find the domain (or addon domain) that sends the mail.
  4. If SPF is not valid, click Repair or Manage.
  5. Confirm the suggested string starts with v=spf1 and ends with ~all or -all.

If the domain is in cPanel Hosting DNS mode, Repair can write the TXT for you. Do not also paste a second SPF in the Zone Editor.

If the domain uses AtlasDNS, Repair shows the value the mail server expects but does not publish it on AtlasDNS. Copy the full string and add it under Domains → the domain → DNS.

The hostname is typically mail.yourdomain.com when this account sends the mail. A typical cPanel-shaped record looks like this (use the IP Email Deliverability shows, not this documentation address):

v=spf1 +a +mx +ip4:192.0.2.10 ~all

Enable SPF on LochStudios Mail

  1. Sign in at /portal.
  2. Open the mail service for the domain.
  3. Copy the SPF value shown there (the full v=spf1 string).
  4. Add or replace the root TXT on Domains → the domain → DNS (or in the Zone Editor only if the domain is in cPanel Hosting DNS mode).

If the mail service does not show an SPF value, open a support ticket and we will publish it with you.

The record we publish for this product looks like:

v=spf1 +a +mx +include:spf.ax.email ~all

Keep include:spf.ax.email in the string for as long as LochStudios Mail sends as the domain. Plans are on LochStudios Mail. Hostname is usually mail.yourdomain.com once DNS and MX point at this product.

What the record looks like

Publish one SPF string on the root name.

TypeNameValue
TXT@v=spf1 +a +mx +include:spf.ax.email ~all

On AtlasDNS the name field is @ (or blank), not the full yourdomain.com, unless the form asks for the FQDN. Do not wrap the value in extra quotes unless the form adds them for you.

Building blocks:

  • v=spf1 - Version. Always first.
  • ip4:192.0.2.10 - Authorises that IPv4 address (or a CIDR range such as ip4:192.0.2.0/24).
  • ip6: - Authorises an IPv6 address or range.
  • a - Authorises the A (and AAAA) address of this name. Useful when the website IP also sends mail.
  • mx - Authorises the hosts in this domain's MX records.
  • include:example-sender.com - Also trust the SPF published on that other name. Use the include the product gave you.
  • ~all - Soft fail. Unlisted senders do not pass. Start here while you are still adding services.
  • -all - Fail. Use this once every real sender is in the string.

Do not end with +all. That authorises the whole internet.

A merged example (shared hosting IP plus a newsletter include) looks like:

v=spf1 +a +mx +ip4:192.0.2.10 include:newsletter.example ~all

Record types: DNS record types explained.

Other senders on the same domain

A newsletter tool, a contact form, or another mail product must appear in the same string. Add their include: or ip4: just before ~all or -all. Leave our mechanisms in place if we still send as that domain.

  • One v=spf1 TXT per name. Two SPF records invalidate both.
  • Each include, a, and mx counts toward SPF's limit of 10 DNS lookups. Too many includes and the check fails. Prefer that product's single include over a long list of IPs they already publish.
  • Do not copy a third-party SPF in place of ours unless you have stopped sending from that product.

If you are not sure how to merge the string, open a support ticket and list every system that sends as the domain.

Check that it works

DNS changes are often quick. They can take a while to show everywhere. See DNS propagation explained.

Look up the published record (use your real domain):

nslookup -type=TXT yourdomain.com

You should see one v=spf1 string, matching what you saved.

Then send a real message from the mailbox that should be authorised.

  • Shared hosting: Access Webmail (Roundcube), or a mail app.
  • LochStudios Mail: Log in to WebMail on the mail service.

Send it to an inbox you control. In Gmail, open the message, use the three-dot menu, choose Show original, and look for SPF=PASS (and a domain that matches the envelope you expect).

If you would rather we check, open a support ticket and include the domain and the mail product.

Good habits

  • One SPF string per name. Edit the existing TXT when you add a sender.
  • Start with ~all. Move to -all after a week of clean tests.
  • Update the string before a new tool starts sending, not after mail is already failing.
  • Keep the envelope domain aligned with the From domain if you want DMARC to pass on SPF.
  • Do not use ptr mechanisms. They are slow and unreliable.
  • A subdomain that sends as itself (news@mail.yourdomain.com) needs its own SPF on that name. Addresses that send as the root domain use the root record.

Keep mail, website, and authentication records on AtlasDNS (or on cPanel Hosting if that is the live mode). See Point your domain at your hosting.

If something looks wrong

The lookup shows two v=spf1 values. Delete the extra TXT. Merge any missing include: or ip4: into the one you keep.

"Too many DNS lookups." Remove unused includes. Use each product's single include that already wraps their IPs. If you cannot get under the limit, open a support ticket.

Your own mail is treated as spam. That sender's IP is not in the string, or you are editing the wrong zone (AtlasDNS versus cPanel Hosting). Confirm MX still points at the product that sent the message. SPF alone is not enough: add DKIM and then DMARC.

The new value is not visible yet. Wait for propagation, then look up again. Confirm you saved on the live nameservers.

The lookup says the record is invalid. v=spf1 must be first. Use spaces between mechanisms. Do not put two all terms at the end. Do not invent an include hostname.

A VPS or form plugin sends as the domain. Add that host's ip4: (from the portal for a VPS) or the plugin's include. Website PHP mail() on shared hosting is usually covered by a / mx / the account IP once Email Deliverability has written the record.

If mail still does not authenticate after the lookup looks right, open a support ticket. Include the domain, the mail product, and a recent TXT lookup.

Next steps

Once this TXT matches a real send, enable DKIM on the same product, then add a DMARC record starting at p=none. We can set all three with you if you open a support ticket.

If mail is not arriving at all, start with Email is not sending or receiving.

Related


Was this article helpful?

← Back to Email Deliverability