How do I set up SPF for Google Workspace?

Updated 9 October 2026 · 5 min read

Guest list

Add one TXT record at your DNS provider for yourbusiness.com with the value v=spf1 include:_spf.google.com ~all. If your domain already has an SPF record, don't add a second one: add include:_spf.google.com to the record you have.

What SPF does for Google Workspace email

SPF is a DNS record that lists the servers allowed to send email for your domain. DNS is the public address book for your domain, kept by your DNS provider, which is usually where you bought the domain, your website host, or Cloudflare.

When Gmail, Yahoo or Outlook receives an email from you, it checks whether the sending server is on that list. include:_spf.google.com adds all of Google's sending servers in one go.

Gmail and Yahoo require every sender to pass SPF or DKIM, and bulk senders to have both. Google Workspace uses your own domain as the hidden bounce address, so a passing SPF check also counts toward DMARC for yourbusiness.com.

Before you start

You don't need the Google Admin console: Google says SPF is set up entirely at your DNS provider. If you bought your domain from a Google partner when you signed up, SPF may already be in place, so check first.

Step 1: List everything that sends email as you

Your SPF record has to cover every service that sends from an @yourbusiness.com address, not just Google: a newsletter platform, your online store or booking system, your website's contact form, even a copier that emails scans. Each service's help pages say which include: to add, if it needs one.

Step 2: Check for an existing SPF record

Sign in to your DNS provider and look at the TXT records for yourbusiness.com. An SPF record starts with v=spf1.

  • None: go to Step 3.
  • One, or more than one: go to Step 4.

Google's Admin Toolbox Check MX tool also shows your SPF record and how many DNS lookups it needs.

Step 3: Create the record (no SPF yet)

TypeName (Host)Value
TXTyourbusiness.comv=spf1 include:_spf.google.com ~all

Most DNS providers want @ in the Name field for the domain itself. Some want it left blank.

Step 4: Merge Google into an existing record

A domain can have only one SPF record. With two, the SPF check fails with an error for every email you send, and Google warns this can send your email to spam.

Keep v=spf1 at the start and the all at the end, and put every include: in between. Say your web host added this record years ago:

v=spf1 include:secureserver.net ~all

Edit it, don't add a new one, so it becomes:

v=spf1 include:secureserver.net include:_spf.google.com ~all

If you have two records, combine their includes into one record like this and delete the other. Order doesn't matter. Remove includes for services you no longer use too. If you moved from Microsoft 365, for example, include:spf.protection.outlook.com can go once nothing sends from there.

The 10-lookup limit

Each include: makes the receiver do a DNS lookup, as does any a, mx, ptr, exists or redirect. Includes inside includes count too. The SPF standard allows 10; go over and SPF fails with an error, as if the record were broken. ip4:, ip6: and all don't count.

Google's include currently uses one lookup, but some services use several each. If you're over:

  1. Remove includes for services you no longer use.
  2. Check whether a service needs to be in SPF at all (see below).
  3. Ask the service for a smaller ("flattened") include.

~all or -all?

The last part of the record says what to do with email from servers that aren't listed:

EndingWhat it tells receivers
~allSoft fail: accept it, but treat it as suspicious. Google recommends this.
-allHard fail: the email may be rejected.
?allNeutral: SPF proves nothing.
+allAny server in the world may send as you. Never use it.

Stick with ~all. Google says -all can be overly restrictive and cause delivery problems for genuine email. A service you forgot to list is the usual victim. Protection against people pretending to be you comes from DMARC set to quarantine or reject. If your record ends in +all, change it to ~all now.

Other services that send as your domain

Marketing platforms such as Mailchimp and Klaviyo usually send bounces through their own domain. SPF is checked against that domain, not yours, so adding their include doesn't help your email pass DMARC. They need domain authentication, which signs your email with DKIM for your domain. Add an include only when the service's help asks for it.

Each subdomain that sends email, such as mail.yourbusiness.com, needs its own SPF record, and so does each extra domain in Google Workspace.

How to check SPF is working

  • Check a real message. Send from your Google Workspace account to a personal Gmail address, open it, choose Show original from the three-dot menu, and check that SPF shows PASS.
  • Run a full test. Send one email to your private test address. The report shows whether SPF passes for yourbusiness.com, how many lookups your record needs, whether there's more than one record, and whether SPF and DKIM align with your From address. You get a verdict for Gmail, Google Workspace, Outlook.com, Microsoft 365 and Yahoo, with the exact record to publish if anything is wrong.

Google says SPF can take up to 48 hours to start working, though most changes show up within minutes.

What to do next

Gmail and Yahoo require bulk senders to have SPF, DKIM and DMARC. Set up DKIM in the Google Admin console next, then add a DMARC record in monitoring mode:

TypeName (Host)Value
TXT_dmarc.yourbusiness.comv=DMARC1; p=none; rua=mailto:dmarc-reports@yourbusiness.com

Change the rua address to a mailbox you read. Once reports show all your genuine email passing, move to p=quarantine.

Checked against: Google Workspace Admin Help, Set up SPF · Google Workspace Admin Help, About SPF records · Google Workspace Admin Help, Troubleshoot SPF issues · Google Workspace Admin Help, Email sender guidelines · RFC 7208, Sender Policy Framework (SPF).

Questions people ask

Can I have two SPF records?

No. A domain can have only one SPF record. With two, the SPF check fails with an error for every email, so receivers treat SPF as failed. Merge everything into a single record that starts with v=spf1.

Should I use ~all or -all?

Use ~all. Google recommends it. A -all can get genuine email rejected, for example from a service you forgot to list or a message that was forwarded. Once your DMARC policy is quarantine or reject, DMARC does the protecting.

Do I need to do anything in the Google Admin console?

No. SPF is set up entirely at your DNS provider. Google says you don't need to do anything in the Admin console.

Do I need to add Mailchimp or Klaviyo to my SPF record?

Usually not. Most marketing platforms send bounces through their own domain, so SPF is checked against their domain, not yours. They need domain authentication (DKIM) instead. Add an include only when the service's own help tells you to.

How long does SPF take to start working?

Google says it can take up to 48 hours. Most DNS changes show up within minutes, so send a test email once the record is saved and check again later if it hasn't appeared.