Email security and anti-spoofing
Pages
Page 8 of 14
Create and iterate an SPF record
SPF works by providing domain owners a way to publish a list of the IP addresses which should be trusted for a given domain. A receiving email service can then check that a sending email service has an IP address which appears in the sender's published list.
If the IP address appears in the list of acceptable IPs, the receiving email service will forward the email to the recipient's inbox. If the receiving email service cannot confirm the IP address is valid, then it marks the email in accordance with the DMARC policy you have implemented on the domain the email is being sent from.
Create an SPF record
Create an SPF record in your public DNS, using all the IP addresses or address ranges from which you send email. You can use both IPv4 and IPv6 addresses. 3 examples of what an SPF record could look like are below:
1. An example of a basic SPF record to be added to an organisation's public DNS where it uses Google would look like this:
v=spf1 include:_spf.google.com ~all
2. This SPF record includes Google's IP ranges and a sending service with an IP address range:
v=spf1 include:_spf.google.com ip4:80.88.21.0/20 ~all
3. An example of a more complex record, with additional services and some dedicated IP addresses:
v=spf1 include:spf.protection.outlook.com include:mail.zendesk.com ip6:2001:db8::/32 ip4:203.0.113.6 ~ all
NOTE: These examples are unique - you cannot just "copy and paste" them into your DNS for your organisation. If you use other email sending services, you need to add their domain or IP range to this record.
You will need to check with your supplier to find the exact value in your case as it will not necessarily take this form (you can usually do this online, we recommend you search your email sending service and how to setup SPF records).
Choosing emailing services
When choosing services, look for ones that can provide an SPF record you can include, or a stable IP range. This will make it easier to maintain your SPF record.
Add all legitimate sources of email to your SPF records
You should ensure that all legitimate IP addresses are added to your SPF records. We recommend that you consult all departments across your organisation and ask, for example, whether they use any 3rd party mailing agents. If your organisation sends mass emails (for example, e-newsletters, e-magazines or e-bills), then it probably uses a 'mass marketing email service'.
Mass marketing email services
Email marketing services allow bulk-sending of emails to targeted mailing lists. If your communications, sales and/or marketing staff make use of this kind of service, you need to ensure they are sending authenticated mails, as this will make it less likely your legitimate marketing emails will end up as spam. That is, you need to ensure that you add the IP addresses to your SPF records and set up DKIM.
There are many such services. The Further reading section links to guidance on email authentication from two of the biggest: MailChimp and SendInBlue.
Understanding and overcoming SPF limitations
SPF record size limit of 450 bytes or fewer
The SPF protocol limits the size of its record to 450 bytes (ie characters) or fewer. If your software does not provide a character count, which should include spaces, we recommend you search online for 'character counter' and confirm that your proposed SPF record is 450 bytes or fewer.
Where your SPF record is greater than 450 bytes, we recommend that you create one or more sub-domains (see below).
DNS lookup restrictions
As part of evaluating whether an email message passes SPF authentication, a receiving mail server may have to make one or more DNS lookups.
To check whether an email passes SPF authentication, receiving mail servers invariably have to undertake DNS lookups. The SPF protocol has some built-in protection – it protects receiving mail servers from denial of service attack by limiting the number of domain lookups to 10.
The DNS lookup limit is often breached by 'nested' lookups caused by the use of an 'include'. In the example above, whereby the SPF record includes _spf.google.com, looking up the contents of this record in DNS we find that it includes 3 google.com subdomains (ie a total of 4 lookups). However, 'includes' are useful because they help overcome the above mentioned SPF record limit of 450 bytes or fewer.
Your organisation might use a number of cloud services, Zendesk, Google Apps, mass mailing services, and so on – rapidly the 10 lookup restriction is breached.
Use your tools
Anti-spoofing management tools, including the NCSC Mail Check platform, often include inline advisory messages and notify you where these SPF restrictions have been breached.
Creating sub-domains
Sub domains will help you overcome the 450 bytes and maximum of 10 DNS lookup restrictions
Each sub-domain makes its own DNS request, and so has its own lookup and character limits. This gives you a tool to split off your various business functions into their own subdomains, each with 10 lookups and 450 characters.
If you use 3rd party suppliers to send emails for you, we recommend creating a sub-domain each. For example, marketing.yourorganisation.gov.uk for your mass mail outs and newsletters.
Not only do you solve the SPF problem, but by doing this, you gain greater visibility and control of each domain. And, if you identify fraudulent use, for example, you will be able to take quicker preventative action, limiting the negative impacts of legitimate email traffic on your other domains.

SPF Errors
SPF syntax is very sensitive to white space. This is one of the most common causes of errors in SPF records. In particular, the failure to put a spaces between the SPF terms (eg between IP addresses).
We recommend that you either leave your draft public DNS record for a few hours and then double-check it, or ask a colleague to double-check it, before you publish it.
The NCSC has guidance on the best practices for secure design and development.
Passing SPF alignment checks
It is important to check if your SPF configurations are also passing an ‘alignment check’. An alignment check is in addition to the standard SPF check described above.
What is SPF alignment?
There are two ‘from’ addresses included on the emails you send from your domain. An SPF alignment check will simply assess if the domain used in these two addresses are the same. You are vulnerable if the two addresses are not in alignment.
For SPF, the two following ‘from’ addresses on the email are assessed:
- The ‘Header From’ address. This is the address that the recipient sees. (eg ‘[email protected]’)
- The ‘Envelope From’ address. This is usually not visible to the recipient. Note: this can also be referred to as the Return-Path address or Bounce address, or Mail From address
How does SPF alignment work?
The following are the most common scenarios you will come across for SPF alignment:
- Emails are failing SPF alignment. If you are using ‘example.co.uk’ in the Header From address, but using ‘outlook.com’ in the Envelope From address, then you are failing SPF alignment in all situations.
- Emails are passing SPF ‘relaxed’ alignment. Most commonly, the default position for alignment checks is ‘relaxed’. This means if you are using ‘example.co.uk’ or a subdomain like ‘mail.example.co.uk’ in the Header From address, and then using ‘example.co.uk’ in the Envelope From address, then SPF alignment checks are passed.
- Emails are failing SPF ‘strict’ alignment. If an organisation has added the term ‘aspf=s’ to their DMARC policy, then alignment checks need to be ‘strict’. A strict alignment policy will mean that the two domains used must be exactly the same. So in this case, if you are using ‘mail.example.co.uk’ in the Header From address, but using ‘example.co.uk’ in the Envelope From address, then this now fails alignment.
How to test and address alignment issues
If you have set up a DMARC reporting tool, any issues with alignment will be raised through that. To fix any issues arising, you will have to consult your technology provider for specific instructions on how to address SPF alignment issues for your email sending system.


