SPF
SPF (Sender Policy Framework) is an email authentication standard that lets a domain publish which servers may send mail on its behalf, helping receivers reject forged senders.
SPF — Sender Policy Framework — is the oldest of the three email authentication standards. A domain owner publishes a DNS TXT record listing the IP addresses and services authorized to send email for that domain. When a message arrives, the receiving server checks the connecting sender's IP against that list: a match passes, anything else fails or soft-fails according to the policy the domain declared.
How it works
The SPF record is a single line of DNS — v=spf1 include:_spf.google.com -all, for example — that enumerates legitimate sending infrastructure: the company's mail servers, its marketing platform, its CRM, its ticketing system. The trailing qualifier states how strictly receivers should treat everything else, from -all (hard fail) to ~all (soft fail). Because the check runs against the envelope sender during the SMTP conversation, it costs receivers almost nothing and happens before the message body is even transmitted.
What it does not stop
SPF validates the hidden envelope address, not the From header a human actually reads — so a message can pass SPF while displaying any name and domain in the visible sender field. It also breaks on ordinary forwarding, because the forwarding server's IP is not in the original domain's list. And it says nothing about message integrity: a passing message may have been altered in transit. These gaps are why SPF alone never stopped spoofing, and why it is paired with DKIM signatures and a DMARC policy that ties authentication to the visible From domain. Attackers running business email compromise campaigns routinely send from free webmail or lookalike domains that pass SPF perfectly — authentication confirms the sending infrastructure, not the sender's intent.
How to defend
- Publish SPF for every domain you own — including domains that send no mail, which get a deny-all record (
v=spf1 -all) so they cannot be forged. - Keep the record current and under the 10-DNS-lookup limit. Stale includes from abandoned SaaS tools are a common silent failure.
- Treat SPF as one layer of three. Deploy DKIM and DMARC on top, then train finance and executive teams on the attacks authentication cannot see — our BEC defense playbook covers that human layer.
Related terms
NOUSEC simulates attacks across 8 channels and turns the results into one number your board can read.
Book a demo