IT security

SPF

Also known as: Sender Policy Framework

In short

SPF is a DNS record that states which servers are allowed to send email on behalf of a domain.

SPF (Sender Policy Framework) is a record in a domain's DNS listing the mail servers authorised to send messages with that sender domain. On arrival, the receiving server looks up the record and compares it with the IP address the message actually came from. If the two do not match, the message counts as unauthorised.

In practice a company rarely sends from one server only: the mail provider, the newsletter tool, the ERP system with its invoice mails and sometimes a copier sending scans all appear under the same domain. Every one of these senders has to be in the SPF record, otherwise their mail ends up in recipients' spam folders.

Two mistakes are common: several SPF records side by side — exactly one is allowed, otherwise the check becomes invalid — and an ending of `?all` or `+all`, which waves through practically any sender and renders the record worthless. SPF also says nothing about the sender name visible in the mail client; only together with DKIM and DMARC does it add up to real protection.

What it means in practice

In many companies the SPF record was set once when moving to a new mail provider and never touched again — even though three more systems now send mail. The sign is that invoice or form mails regularly land in spam for some recipients. NDVDL's free email check reads the public record and shows what is in it.

Is this handled properly at your site?

We look at how it actually stands with you — and say honestly whether anything needs doing.

IT security & firewall

A term from your quote missing here?

Send us the passage you do not follow. We will explain it — with no obligation to order anything.