SPF and DMARC Record Generator (Copy and Paste)
Build a ready-to-paste SPF record and DMARC record from your providers and policy. Free, no sign-up, with plain-language guidance.
Free with no sign-up. Everything runs in your browser: nothing is uploaded or stored.
1. SPF: who may send as your domain?
Tick every service that sends email using your domain. If you are not sure, check the sent folder of that service or ask it for its SPF setup instructions.
How strict should the record be?
Soft fail (~all) marks unlisted senders as suspicious, which is safer while you find every service. Once you are confident the list is complete, switch to -all.
Type TXT, host @
v=spf1 include:_spf.google.com ~all
Add this as a TXT record. A domain can only have one SPF record, so if a record already exists, merge the includes into it instead of adding a second.
2. DMARC: what should receivers do when a check fails?
Policy
Watch only. Failing messages are still delivered, but reports show who sends as your domain.
Type TXT, host _dmarc
v=DMARC1; p=none
Add this as a TXT record on the _dmarc host. Start with p=none to collect reports, then tighten to quarantine and reject.
Provider include values checked against first-party documentation on 2026-10-03. If your provider is not listed, use the include value from its own setup guide.
How it works
- Tick the services that send email using your domain, or paste an include from any other provider.
- The tool builds one SPF record with an include for each service.
- Pick a DMARC policy and, optionally, a report address.
- Copy each record and paste it into your DNS provider as a TXT record.
Where the records go
Both are TXT records. The SPF record uses the host @ (your root domain). The DMARC record uses the host _dmarc. Your DNS provider asks for a type, a host or name, and a value: paste the record exactly as shown.
A domain can only have one SPF record. If one already exists, do not add a second: edit the existing record and merge the includes. Two SPF records can invalidate both. Field values for each provider are taken from its own documentation and checked on the date shown on the page.
After pasting, confirm everything with the authentication checker, then work through the deliverability checklist for the rest of the setup.
Frequently asked questions
I already have an SPF record. Do I add another one?
No. A domain can only have one SPF record, and two records can invalidate both. Edit your existing record and merge the includes shown by the generator into it.
Should I use ~all or -all?
Use ~all (soft fail) while you are still discovering every service that sends as your domain, because it marks unlisted senders as suspicious instead of blocking them. Once the list is complete, switch to -all so unlisted senders are rejected.
What DMARC policy should I start with?
Start with p=none plus a report address. It changes nothing about delivery but shows you every sender, including ones you forgot. After a few weeks of clean reports, move to p=quarantine and then p=reject.
Why does the SPF page warn about too many includes?
Each include costs a DNS lookup and the limit is 10 per SPF check, with nested includes adding more. Around 8 includes it is worth moving marketing senders to a subdomain with its own SPF record.
Answer every email. Approve every send.
Connect Gmail, name your labels, and approve your first AI draft today.
14-day free trial
No credit card
Nothing sends without approval
Disclaimer: these free tools are provided for general information only, as-is and without warranties of any kind. They are not legal, compliance, security, financial, or other professional advice, and no result is a guarantee that a message will be delivered, accepted, or compliant. You are responsible for reviewing every result before relying on it or sending anything based on it. To the maximum extent permitted by law, Tutti accepts no liability for any loss or damage arising from the use of these tools or from reliance on their output. Your use is also governed by our Terms of Service.