SPF is the list of servers allowed to send e-mail on behalf of your domain. Why that decides whether your message lands in spam is covered elsewhere: SPF, DKIM and DMARC, and why your mail lands in spam.
This article repeats none of that. It shows only how the record is created and changed here, field by field, and how you check it afterwards.
The short way: the deliverability tool
cPanel has a tool built for exactly this. It audits the domain, tells you what is missing and, when the DNS is ours, fixes it itself. Use it before editing records by hand: it is faster and it makes fewer mistakes than you will.
| 1 |
Open cPanel from My MozOut and search for Email Deliverability.
|
|
| 2 |
The page lists the domains on the account. Beside each one it says "No problems exist on this domain", and there is nothing to do, or "Problems Exist".
|
|
| 3 |
For the ones with problems, click Manage the Domain. The page shows the state of DKIM, SPF and reverse DNS, and beside each the record that should be there.
|
|
| 4 |
If the domain’s DNS is ours, the tool offers to write the record for you and asks you to confirm first. That is the recommended route.
|
|
| 5 |
If the DNS is at another provider, the tool says it cannot repair it, because this server is not the owner of the zone. Copy the suggested value and create the record over there.
|
|
|
Reverse DNS shows on this page too, but cannot be installed from here: the tool says so itself. If that is your problem, see PTR and reverse DNS.
|
When the suggestion is not enough: customising it
The line the tool suggests covers the normal case: mail leaves from here and nothing else sends in your name. If you have a shop, an invoicing system or a campaign platform sending for you, they have to be added. The domain page has a Customize an SPF Record option, and it asks for exactly this:
| Field |
What goes there, and when |
| Additional Hosts |
Names whose address counts as authorised. Use it when a service gives you a machine name. |
| Additional MX Servers |
Domains whose mail servers count as authorised. Approves everything that receives mail for that domain, in one go. |
| Additional IP Address Blocks (IPv4) |
IPv4 addresses or blocks. Use it when a service gives you a fixed IP. |
| Additional IP Address Blocks (IPv6) |
The same, for IPv6. |
| Include List (INCLUDE) |
The field that matters most. This is where external services that send for you go. Each of them publishes its own list and you simply point at it. The exact value comes from that service. |
| Exclude All Other Hosts |
A checkbox. Ticked, the record ends in -all and tells the world to refuse anything from anywhere else. Unticked, it ends in ~all, which says "be suspicious" rather than "refuse". |
As you fill it in, the page shows the finished line under Preview of the Updated Record. Read it before saving with Install a Customized SPF Record.
Reading the line that comes out
The usual cPanel suggestion for a domain hosted here is v=spf1 +mx +a ~all. Piece by piece:
| Piece |
What it says |
| v=spf1 |
The version. It has to come first, always. A record that does not start this way is not an SPF record. |
| +mx |
The servers that receive mail for this domain may also send it. |
| +a |
The domain’s own address is authorised. |
| include: |
"Ask that service’s list as well." It is what the Include List box writes. |
| ip4: / ip6: |
An authorised address or block, written out by hand. |
| ~all |
Everything else is suspect, but not refused. This is where you start. |
| -all |
Everything else is refused. Only once you are certain the list is complete. |
|
A domain may have only one SPF record. Adding a new service means adding to the line that already exists. Creating a second record adds nothing: the two cancel out, and the result is worse than having none.
|
|
There is a ceiling on lookups. Every include:, every a and every mx forces the receiver to go and ask. Past that ceiling the check fails for everybody, and it fails silently. So do not let includes for services you no longer use pile up: clear them out.
|
By hand, when the DNS lives elsewhere
SPF is an ordinary TXT record and is created like any other. The mechanics are the same as for verification codes: creating a TXT record, step by step.
| 2 |
Create a record of type TXT. For the name, use the domain itself, not a subdomain.
|
|
| 3 |
For the value, paste the whole line, starting at v=spf1, with no stray spaces and not split in two.
|
|
| 4 |
Save, then go back to the cPanel deliverability tool. It rechecks and should now report the domain as clean.
|
|
Checking it from outside
| System |
Command |
| Windows |
nslookup -type=TXT yourcompany.com at the command prompt |
| macOS or Linux |
dig TXT yourcompany.com +short in Terminal |
Look in the answer for the line starting with v=spf1. There should be one, and only one. If you just saved and still see the old one, it is probably fine: how long propagation takes.
|
Tell us which services send e-mail in your domain’s name and we will send back the complete SPF line, ready to paste.
Open a support ticket
|
RECOMMENDED PRODUCT Web hosting with cPanel Domain and SSL included, daily backups and the panel you already know. from $10.00/mo See plans |