Add one TXT record at your DNS provider for yourbusiness.com with the value v=spf1 include:_spf.google.com ~all. If your domain already has an SPF record, don't add a second one: add include:_spf.google.com to the record you have.
What SPF does for Google Workspace email
SPF is a DNS record that lists the servers allowed to send email for your domain. DNS is the public address book for your domain, kept by your DNS provider, which is usually where you bought the domain, your website host, or Cloudflare.
When Gmail, Yahoo or Outlook receives an email from you, it checks whether the sending server is on that list. include:_spf.google.com adds all of Google's sending servers in one go.
Gmail and Yahoo require every sender to pass SPF or DKIM, and bulk senders to have both. Google Workspace uses your own domain as the hidden bounce address, so a passing SPF check also counts toward DMARC for yourbusiness.com.
Before you start
You don't need the Google Admin console: Google says SPF is set up entirely at your DNS provider. If you bought your domain from a Google partner when you signed up, SPF may already be in place, so check first.
Step 1: List everything that sends email as you
Your SPF record has to cover every service that sends from an @yourbusiness.com address, not just Google: a newsletter platform, your online store or booking system, your website's contact form, even a copier that emails scans. Each service's help pages say which include: to add, if it needs one.
Step 2: Check for an existing SPF record
Sign in to your DNS provider and look at the TXT records for yourbusiness.com. An SPF record starts with v=spf1.
- None: go to Step 3.
- One, or more than one: go to Step 4.
Google's Admin Toolbox Check MX tool also shows your SPF record and how many DNS lookups it needs.
Step 3: Create the record (no SPF yet)
| Type | Name (Host) | Value |
|---|---|---|
| TXT | yourbusiness.com | v=spf1 include:_spf.google.com ~all |
Most DNS providers want @ in the Name field for the domain itself. Some want it left blank.
Step 4: Merge Google into an existing record
A domain can have only one SPF record. With two, the SPF check fails with an error for every email you send, and Google warns this can send your email to spam.
Keep v=spf1 at the start and the all at the end, and put every include: in between. Say your web host added this record years ago:
v=spf1 include:secureserver.net ~all
Edit it, don't add a new one, so it becomes:
v=spf1 include:secureserver.net include:_spf.google.com ~all
If you have two records, combine their includes into one record like this and delete the other. Order doesn't matter. Remove includes for services you no longer use too. If you moved from Microsoft 365, for example, include:spf.protection.outlook.com can go once nothing sends from there.
The 10-lookup limit
Each include: makes the receiver do a DNS lookup, as does any a, mx, ptr, exists or redirect. Includes inside includes count too. The SPF standard allows 10; go over and SPF fails with an error, as if the record were broken. ip4:, ip6: and all don't count.
Google's include currently uses one lookup, but some services use several each. If you're over:
- Remove includes for services you no longer use.
- Check whether a service needs to be in SPF at all (see below).
- Ask the service for a smaller ("flattened") include.
~all or -all?
The last part of the record says what to do with email from servers that aren't listed:
| Ending | What it tells receivers |
|---|---|
| ~all | Soft fail: accept it, but treat it as suspicious. Google recommends this. |
| -all | Hard fail: the email may be rejected. |
| ?all | Neutral: SPF proves nothing. |
| +all | Any server in the world may send as you. Never use it. |
Stick with ~all. Google says -all can be overly restrictive and cause delivery problems for genuine email. A service you forgot to list is the usual victim. Protection against people pretending to be you comes from DMARC set to quarantine or reject. If your record ends in +all, change it to ~all now.
Other services that send as your domain
Marketing platforms such as Mailchimp and Klaviyo usually send bounces through their own domain. SPF is checked against that domain, not yours, so adding their include doesn't help your email pass DMARC. They need domain authentication, which signs your email with DKIM for your domain. Add an include only when the service's help asks for it.
Each subdomain that sends email, such as mail.yourbusiness.com, needs its own SPF record, and so does each extra domain in Google Workspace.
How to check SPF is working
- Check a real message. Send from your Google Workspace account to a personal Gmail address, open it, choose Show original from the three-dot menu, and check that SPF shows PASS.
- Run a full test. Send one email to your private test address. The report shows whether SPF passes for yourbusiness.com, how many lookups your record needs, whether there's more than one record, and whether SPF and DKIM align with your From address. You get a verdict for Gmail, Google Workspace, Outlook.com, Microsoft 365 and Yahoo, with the exact record to publish if anything is wrong.
Google says SPF can take up to 48 hours to start working, though most changes show up within minutes.
What to do next
Gmail and Yahoo require bulk senders to have SPF, DKIM and DMARC. Set up DKIM in the Google Admin console next, then add a DMARC record in monitoring mode:
| Type | Name (Host) | Value |
|---|---|---|
| TXT | _dmarc.yourbusiness.com | v=DMARC1; p=none; rua=mailto:dmarc-reports@yourbusiness.com |
Change the rua address to a mailbox you read. Once reports show all your genuine email passing, move to p=quarantine.
Checked against: Google Workspace Admin Help, Set up SPF · Google Workspace Admin Help, About SPF records · Google Workspace Admin Help, Troubleshoot SPF issues · Google Workspace Admin Help, Email sender guidelines · RFC 7208, Sender Policy Framework (SPF).