security / email authentication / spf
Email authentication

SPF

SPF lets you publish a list of mail servers that are allowed to send email for your domain, so receiving servers can spot forgeries.

Severity if missing
High
Category
Email authentication
Standard
RFC 7208

What it is

SPF (Sender Policy Framework) is a DNS record that names every server permitted to send email on behalf of your domain. When a mail server receives a message claiming to be from you, it checks the sending server against that list.

If the sending server is on the list, the message passes SPF. If it isn't, the record also tells the receiver how strict to be — from "let it through anyway" to "treat it as a failure".

Why it matters

Email was never designed with security in mind — by default, any server can claim to send mail as your domain. SPF is the first line of defence against that. Without it, spammers and phishers can forge your address freely, and your legitimate mail is also more likely to land in spam because receivers can't verify it.

The risk
A missing SPF record, or one ending in ~all (SoftFail) instead of -all (HardFail), means forged emails from your domain are still delivered. Attackers can impersonate you with little resistance.

How Pentrawl checks it

Pentrawl reads the SPF (TXT) record for your domain and inspects how it ends. We report a pass for -all (HardFail), a warning for ~all (SoftFail), and an issue for a missing record or a weak policy such as ?all or +all.

How to fix it

Publish a single SPF record as a TXT record on your domain. Include every service that sends mail for you (your mail host, marketing tools, etc.), then end it with a strict policy once you're sure the list is complete.

Recommended
yourdomain.com. TXT "v=spf1 include:_spf.yourprovider.com -all"
Softer — while testing
yourdomain.com. TXT "v=spf1 include:_spf.yourprovider.com ~all"

Related checks

Check your domain's SPF in seconds
Pentrawl scans this and 20+ other security checks in one automated pass.
Scan your website →