Back to the knowledge base
Authenticatiespfdns

Adding an SPF record at your DNS provider

An SPF record tells receiving mail servers which servers may send on behalf of your domain. Without 2Mail in that record, a recipient treats mail through our relay as suspicious. You add the record in the DNS management of your registrar or hosting panel — not with us — and the 2Mail dashboard shows you the exact value.

Step 1: get the value

Open your sending domain in the 2Mail dashboard. Under authentication you see the SPF entry you need to include: a short include reference to 2Mail. Copy it literally.

Step 2: check whether an SPF record already exists

Look in the DNS management of your registrar or hosting panel for a TXT record on your domain that starts with v=spf1. If there already is one — for example for your mail provider — add our include reference to that existing record, before the closing -all or ~all. Never create a second SPF record: with two records the check fails for every sender, including the old ones.

Step 3: create or edit the record

  1. Choose TXT as the type.
  2. Enter the domain itself as the name. In most panels that is an at sign or an empty field; do not type the domain in again.
  3. Paste the full value, from v=spf1 up to and including the closing all. Leave out the quotes if the panel adds them itself.
  4. Save and leave the TTL as it is.

Step 4: check in the dashboard

Go back to your sending domain in the dashboard and let 2Mail check the record. A new record is usually visible within the hour; a changed record takes as long as the old TTL. Once the check turns green, mail through our relay leaves with a positive SPF result.

Where it goes wrong

  • Two records — the most common mistake. Merge them into one.
  • Too many lookups — an SPF record may only contain a limited number of include references. Clean up services you no longer use.
  • Record on the wrong domain — SPF belongs on the domain of your sender address, not on the domain of your website if they differ.
  • Tested too soon — your own computer remembers the old answer. Trust the check in the dashboard.

SPF alone is not enough: combine it with DKIM and DMARC. The steps are in activating a DKIM key, the background on SPF, DKIM and DMARC.

Still stuck?

Send us your domain name and a screenshot of the record as it appears in your panel via contact. We tell you what needs to change.

#add spf record#spf record dns#create spf record#spf include#two spf records
Still stuck?

Does it behave differently than described above, or are you stuck anyway? Get in touch with your domain name or customer number at hand and we will take a look with you.

Contact support
Call us
Send an email