🛡️ RFC 7208 & RFC 7489 Deliverability Engine

SPF & DMARC Record Generator

Generate valid DNS TXT records to meet Google & Yahoo sender authentication rules. Avoid spam folders and prevent email spoofing with zero tracking.

⚙️ Domain & Sender Configuration ✓ Self-Test: 5/5 Passing
📋 Ready-to-Copy DNS TXT Records
RFC 7208 DNS Lookups: 2 / 10 (Safe) ✓ Pass
DMARC Record (TXT) _dmarc.example.com
v=DMARC1; p=quarantine; rua=mailto:dmarc-reports@example.com; pct=100
SPF Record (TXT) example.com (or @)
v=spf1 include:_spf.google.com include:resend.com ~all
🔥 Popular Infrastructure & Webmaster Utilities

The Critical 2024-2026 Sender Authentication Mandates

Starting in February 2024 and expanding through 2026, Google (Gmail) and Yahoo enforced strict deliverability requirements for all email senders. Domains sending transactional or bulk emails without aligned SPF, DKIM, and DMARC records face immediate delivery blocks (returning 550-5.7.26 This message does not pass authentication checks) or are routed directly to recipient Spam folders.

The RFC 7208 10-DNS-Lookup Limit Explained

The SPF specification (RFC 7208 Section 4.6.4) strictly limits the number of DNS lookups required to evaluate an SPF record to a maximum of 10. Mechanisms that count against this limit include include:, a, mx, ptr, and redirect (while ip4: and ip6: do not count toward DNS lookups).

If your SPF record triggers more than 10 lookups (for example, combining too many third-party services like Google Workspace, SendGrid, Zendesk, and Salesforce), receiving mail servers will throw an SPF PermError, completely failing authentication even if your records are technically correct.

Frequently Asked Questions (Email Infrastructure FAQ)

❓ Should I use p=none, p=quarantine, or p=reject for DMARC?
Always begin with p=none for 2-4 weeks to monitor aggregate reports (via your rua= address) and verify that all legitimate sending sources (CRMs, transactional APIs, Google Workspace) pass DKIM and SPF. Once alignment is confirmed, transition to p=quarantine (routes spoofed emails to Spam) and ultimately to p=reject (blocks unauthorized senders outright).
❓ What is the difference between ~all (SoftFail) and -all (HardFail) in SPF?
~all (SoftFail) indicates that unlisted servers are suspicious but allows the receiving server to accept the email and apply DMARC evaluation. Google and Yahoo specifically recommend ~all because automated email forwarding (such as mailing lists or aliases) often breaks SPF, and DMARC can still pass via DKIM alignment. In contrast, -all (HardFail) strictly instructs servers to reject the email immediately.
❓ Why does DMARC require a rua email address?
The rua=mailto:... tag specifies where receiving mail servers (Google, Microsoft, Yahoo) send daily XML aggregate reports detailing who sent emails pretending to be from your domain, whether SPF/DKIM passed, and the IP addresses involved.
❓ Can I have multiple SPF TXT records on the same domain?
No! RFC 7208 forbids publishing more than one SPF TXT record on a domain. If a domain has two separate records (e.g. one for Google and one for SendGrid), the recipient server will immediately return an SPF PermError. You must merge all authorized senders into a single v=spf1 ... ~all line.
❓ Where should the DMARC TXT record be created in DNS?
The DMARC record must always be created as a TXT record at the specific subdomain _dmarc (for example, _dmarc.yourdomain.com). Do not put DMARC at the root @ domain.
❓ Does this generator upload or store my domain name?
No. This tool runs 100% in your local browser using client-side JavaScript. Zero domain names, email addresses, or DNS parameters are ever sent to any remote server.
Copied to clipboard!

Frequently Asked Questions

Is SPF & DMARC Record Generator free to use?

Yes, SPF & DMARC Record Generator is completely free with no signup or registration required. All processing happens directly in your browser.

Is my data safe?

Absolutely. Your data never leaves your device. Everything runs locally in your browser — no uploads, no servers, no tracking.

Do I need to install anything?

No installation needed. SPF & DMARC Record Generator works entirely in your web browser on both desktop and mobile devices.

How do I use

Simply enter or paste your input in the tool above, and the result will be generated instantly. No configuration required.

Verified Client-Side