← All terms

SPF

SPF (Sender Policy Framework) is an email authentication standard that lets a domain publish which servers may send mail on its behalf, helping receivers reject forged senders.

SPF — Sender Policy Framework — is the oldest of the three email authentication standards. A domain owner publishes a DNS TXT record listing the IP addresses and services authorized to send email for that domain. When a message arrives, the receiving server checks the connecting sender's IP against that list: a match passes, anything else fails or soft-fails according to the policy the domain declared.

How it works

The SPF record is a single line of DNS — v=spf1 include:_spf.google.com -all, for example — that enumerates legitimate sending infrastructure: the company's mail servers, its marketing platform, its CRM, its ticketing system. The trailing qualifier states how strictly receivers should treat everything else, from -all (hard fail) to ~all (soft fail). Because the check runs against the envelope sender during the SMTP conversation, it costs receivers almost nothing and happens before the message body is even transmitted.

What it does not stop

SPF validates the hidden envelope address, not the From header a human actually reads — so a message can pass SPF while displaying any name and domain in the visible sender field. It also breaks on ordinary forwarding, because the forwarding server's IP is not in the original domain's list. And it says nothing about message integrity: a passing message may have been altered in transit. These gaps are why SPF alone never stopped spoofing, and why it is paired with DKIM signatures and a DMARC policy that ties authentication to the visible From domain. Attackers running business email compromise campaigns routinely send from free webmail or lookalike domains that pass SPF perfectly — authentication confirms the sending infrastructure, not the sender's intent.

How to defend

  • Publish SPF for every domain you own — including domains that send no mail, which get a deny-all record (v=spf1 -all) so they cannot be forged.
  • Keep the record current and under the 10-DNS-lookup limit. Stale includes from abandoned SaaS tools are a common silent failure.
  • Treat SPF as one layer of three. Deploy DKIM and DMARC on top, then train finance and executive teams on the attacks authentication cannot see — our BEC defense playbook covers that human layer.

Related terms

DKIMDKIM (DomainKeys Identified Mail) adds a cryptographic signature to outgoing email, letting receivers verify the message really came from the signing domain and was not altered in transit.DMARCDMARC (Domain-based Message Authentication, Reporting and Conformance) is an email authentication standard that tells receiving servers how to handle messages that fail SPF or DKIM checks, blocking exact-domain spoofing.SpoofingSpoofing is the falsification of an identity signal — sender address, caller ID, domain, or website — to make an attack appear to come from a trusted source.Business Email Compromise (BEC)Business email compromise is a targeted attack where criminals impersonate executives or trusted partners via email to trick employees into transferring money or sensitive data.
See your Human Risk Score

NOUSEC simulates attacks across 8 channels and turns the results into one number your board can read.

Book a demo