Skip to content
Techno Trader
Home

Security & DNS

SPF

Sender Policy Framework records that declare exactly which hosts may send mail for a domain, built from a verified inventory of sending sources rather than guesswork.

SPF sending-source inventory and DNS TXT records reviewed on an engineer console beside a mail relay rack
SENDER POLICY · SPF

Engineering capabilities

  • Sending-source discovery across apps, CRM and marketing tools
  • Record authoring within the ten-lookup limit
  • Flattening and consolidation of nested includes
  • Staged move from softfail to hard fail

Security & hardening

  • Removal of stale include mechanisms and abandoned senders
  • Alignment checked against DMARC before enforcement
  • Change control on the DNS zone holding the record

SPF publication path

A record is only as good as the sending inventory behind it. Sources are discovered first, then declared, then enforced.

  1. 01

    Discovery

    • Tenant senders
    • Application senders
    • Marketing / CRM tools
    • Legacy relays

    Every system that sends as the domain is found before the record is written.

  2. 02

    Record design

    • include: mechanisms
    • ip4 / ip6 entries
    • Lookup budget
    • Flattening

    The ten-DNS-lookup limit is respected; nested includes are consolidated where a provider allows it.

  3. 03

    Publication

    • TXT record
    • TTL control
    • Subdomain policy

    Published with a short TTL during change, then raised once behaviour is stable.

  4. 04

    Enforcement

    • ~all softfail
    • -all hard fail
    • DMARC alignment

    Hard fail only after DMARC reports confirm no legitimate source is missing.

Frequently asked questions

Why is our SPF record failing?

Most often the ten-lookup limit has been exceeded by stacked includes, or a sending platform was added without updating the record. Both show up immediately in DMARC aggregate reports.

Can we have two SPF records?

No. A domain must publish exactly one SPF TXT record; multiple records cause a permanent error and mail starts failing authentication.

Is SPF enough on its own?

No. SPF breaks on forwarding, so DKIM signing and a DMARC policy are needed for the domain to be genuinely protected.

Scope the work before you commit budget

Send the environment details and get an engineered proposal with assumptions, risks and a rollback path.

Request a Quote WhatsApp