Skip to main content
Guidance

Email security and anti-spoofing

A guide for IT managers and systems administrators

Page 8 of 14

Create and iterate an SPF record

Sender Policy Framework (SPF) is a system of email authentication.

SPF works by providing domain owners a way to publish a list of the IP addresses which should be trusted for a given domain. A receiving email service can then check that a sending email service has an IP address which appears in the sender's published list.

If the IP address appears in the list of acceptable IPs, the receiving email service will forward the email to the recipient's inbox. If the receiving email service cannot confirm the IP address is valid, then it marks the email in accordance with the DMARC policy you have implemented on the domain the email is being sent from.


Choosing emailing services

When choosing services, look for ones that can provide an SPF record you can include, or a stable IP range. This will make it easier to maintain your SPF record.



Use your tools

Anti-spoofing management tools, including the NCSC Mail Check platform, often include inline advisory messages and notify you where these SPF restrictions have been breached.

Creating sub-domains

Sub domains will help you overcome the 450 bytes and maximum of 10 DNS lookup restrictions

Each sub-domain makes its own DNS request, and so has its own lookup and character limits. This gives you a tool to split off your various business functions into their own subdomains, each with 10 lookups and 450 characters.

If you use 3rd party suppliers to send emails for you, we recommend creating a sub-domain each. For example, marketing.yourorganisation.gov.uk for your mass mail outs and newsletters.

Not only do you solve the SPF problem, but by doing this, you gain greater visibility and control of each domain. And, if you identify fraudulent use, for example, you will be able to take quicker preventative action, limiting the negative impacts of legitimate email traffic on your other domains.

SPF Errors

SPF syntax is very sensitive to white space. This is one of the most common causes of errors in SPF records. In particular, the failure to put a spaces between the SPF terms (eg between IP addresses).

We recommend that you either leave your draft public DNS record for a few hours and then double-check it, or ask a colleague to double-check it, before you publish it. 

The NCSC has guidance on the best practices for secure design and development.


Published

Reviewed

Version

2.0