Generate valid DNS TXT records to meet Google & Yahoo sender authentication rules. Avoid spam folders and prevent email spoofing with zero tracking.
Starting in February 2024 and expanding through 2026, Google (Gmail) and Yahoo enforced strict deliverability requirements for all email senders. Domains sending transactional or bulk emails without aligned SPF, DKIM, and DMARC records face immediate delivery blocks (returning 550-5.7.26 This message does not pass authentication checks) or are routed directly to recipient Spam folders.
The SPF specification (RFC 7208 Section 4.6.4) strictly limits the number of DNS lookups required to evaluate an SPF record to a maximum of 10. Mechanisms that count against this limit include include:, a, mx, ptr, and redirect (while ip4: and ip6: do not count toward DNS lookups).
If your SPF record triggers more than 10 lookups (for example, combining too many third-party services like Google Workspace, SendGrid, Zendesk, and Salesforce), receiving mail servers will throw an SPF PermError, completely failing authentication even if your records are technically correct.
p=none for 2-4 weeks to monitor aggregate reports (via your rua= address) and verify that all legitimate sending sources (CRMs, transactional APIs, Google Workspace) pass DKIM and SPF. Once alignment is confirmed, transition to p=quarantine (routes spoofed emails to Spam) and ultimately to p=reject (blocks unauthorized senders outright).~all (SoftFail) indicates that unlisted servers are suspicious but allows the receiving server to accept the email and apply DMARC evaluation. Google and Yahoo specifically recommend ~all because automated email forwarding (such as mailing lists or aliases) often breaks SPF, and DMARC can still pass via DKIM alignment. In contrast, -all (HardFail) strictly instructs servers to reject the email immediately.rua=mailto:... tag specifies where receiving mail servers (Google, Microsoft, Yahoo) send daily XML aggregate reports detailing who sent emails pretending to be from your domain, whether SPF/DKIM passed, and the IP addresses involved.SPF PermError. You must merge all authorized senders into a single v=spf1 ... ~all line.TXT record at the specific subdomain _dmarc (for example, _dmarc.yourdomain.com). Do not put DMARC at the root @ domain.Yes, SPF & DMARC Record Generator is completely free with no signup or registration required. All processing happens directly in your browser.
Absolutely. Your data never leaves your device. Everything runs locally in your browser — no uploads, no servers, no tracking.
No installation needed. SPF & DMARC Record Generator works entirely in your web browser on both desktop and mobile devices.
Simply enter or paste your input in the tool above, and the result will be generated instantly. No configuration required.