Skip to main content
.com from $2.99, and WHOIS privacy costs nothing

Learning Hub · Intermediate · 15 minutes

How to Create an SPF Record

Everything you need to declare who may send email as your domain — the steps, the gotcha, and the tip the support desk gives everyone.

The short answer

In one line: declare who may send email as your domain — a intermediate-level job taking 15 minutes.

Below: the exact steps, the classic pitfall, and a pro tip from the support desk. Where our platform automates a step, the guide says so rather than making you do robot work.

Written by the HostingAlly team · Last revised 27 July 2026

Intermediate

Skill level

5

Steps to done

Free

Support included

Tested

On our platform

You don't need to be technical for this — the walkthrough is written for first-timers, tested against our own platform, and honest about which parts are genuinely fiddly versus merely unfamiliar.

Rule of the road: read the gotcha section before you begin, not after — it's harvested from the support tickets of people who didn't.

The shape of the job

Start to finish, you'll inventory every legitimate sender, compose the single txt record, publish at the domain root, mind the lookup budget and verify with a checker.

None of the stages requires code or a terminal unless the guide explicitly says so — and where it does, the exact commands are given. The full step-by-step sits below; the surrounding sections cover the context that makes it stick.

The mistake almost everyone makes

Creating a second SPF record for a new service instead of editing the existing one — duplicate SPF equals no SPF, and deliverability quietly degrades while both records look individually correct.

Forewarned is genuinely forearmed here — this exact mistake accounts for most of the frustration this topic produces, and it's entirely avoidable once named.

The tip we give everyone

End with ~all (softfail) rather than -all until DKIM and monitoring confirm the inventory is complete — strictness is the last step, not the first.

Small habits like this are the real difference between people who find hosting easy and people who find it stressful — the tools are identical; the workflow isn't.

The parts you can skip on our hosting

We've automated the steps that don't deserve your time: certificates issue and renew themselves, the installer handles application setup, daily backups cover the what-if, and per-site settings live in a panel instead of config files. The guide above covers what's left — the part that's actually about your site.

And when a step misbehaves anyway, support answers around the clock — with the actual fix, not a knowledge-base link and a shrug. Half our best guides started as patterns in the tickets.

An inbox sitting open on a laptop, professional business email

Guides are easier on a good platform

Every walkthrough in our Learning Hub is tested on the platform we actually run — cPanel, LiteSpeed, NVMe, one-click installs — so instructions match your screen instead of gesturing at it.

NVMe storage and LiteSpeed caching are standard here, not premium-tier extras.

  • Step-by-step, tested as written
  • The gotcha flagged before you hit it
  • Automation covers the boring steps
  • 24/7 support if you get stuck

Why HostingAlly

Every plan includes this, whatever you pay

5 steps, no filler

Each stage is a few minutes of focused clicking, with the fiddly parts marked as fiddly.

Help on standby

Stuck at step three at midnight? Support answers around the clock, mid-guide included.

Automation where it belongs

SSL, backups and installs run themselves here — the guide covers only what's genuinely yours to do.

No jargon tax

Terms are explained in place or linked to the glossary — nothing assumes you already know.

Scoped honestly

Declare who may send email as your domain is a intermediate-level task — this guide budgets 15 minutes and says which steps the platform absorbs.

The gotcha, named early

The classic mistake for this exact task is flagged before step one — so 15 minutes stays 15 minutes.

Getting Started

How to get going

  1. 1

    Inventory every legitimate sender

    Hosting mail, newsletter platform, CRM, invoicing tool — anything sending as you@yourdomain belongs in the record; the audit is the hard part.

  2. 2

    Compose the single TXT record

    v=spf1 followed by include: mechanisms per service and your host's servers, ending ~all — each service documents its exact include string.

  3. 3

    Publish at the domain root

    One TXT record on @ — one, singular; a second SPF record doesn't extend the first, it invalidates both.

  4. 4

    Mind the lookup budget

    SPF allows ten DNS lookups total; nested includes from many services approach it fast — flattening or pruning keeps validation working.

  5. 5

    Verify with a checker

    An SPF validation tool confirms syntax and lookup count; a test mail to a checker address shows the pass in headers.

Included

What's covered on our plans

  • 24/7 support from real people
  • Staging environments for risk-free changes
  • 30-day money-back guarantee on hosting plans
  • Upgrades apply in place — no migrations between plans
  • 99.9% uptime commitment, monitored around the clock
  • Softaculous one-click app installer
  • Per-site PHP version selection
  • Spam and virus filtering on every mailbox
  • Webmail plus IMAP, POP and SMTP access
  • WordPress Toolkit with automatic updates

FAQ

Your questions, answered

What does SPF actually prevent?

It lets receiving servers check whether the sending server was authorised by your domain — raising the cost of simple spoofing and feeding DMARC's decisions. It's one leg of the SPF/DKIM/DMARC tripod, not a complete defence alone.

My newsletters fail SPF even though I added the include — why?

Usually the platform sends from its own envelope domain (SPF passes on theirs) and alignment fails on yours — the fix is the platform's custom-domain/DKIM setup, which aligns signing with your domain properly.

Which control panel do you provide?

cPanel — the industry standard, which means every tutorial on the internet matches your screen, your backups restore anywhere cPanel runs, and skills learned here transfer for life. Plesk and DirectAdmin options exist on specific plans for those who prefer them.

How long does it take to get started?

Minutes — hosting activates on payment, the domain (free for year one on annual plans) connects immediately, and one-click installers put WordPress or 400+ other apps live the same sitting. If you have an existing site, our team migrates it free, usually within 24 hours.

Can I choose my PHP version?

Yes — PHP versions are selectable per site from the control panel, so a legacy application and a current one can live side by side. Extensions and per-site settings are adjustable in the same place, no support ticket needed.

What does your 24/7 support actually cover?

Real people at every hour, and a scope that includes the practical questions — email setup, DNS, WordPress issues, restores — not just 'the server is up, ticket closed'. Pre-sales questions are welcome too; ask us something difficult and judge the reply.

Can I host more than one website on a plan?

On the Pro tier and above, yes — multiple sites with their own domains, email and SSL under one account. If the extra sites belong to clients rather than you, reseller hosting gives each one proper isolation instead.

Planning to switch hosts? Grab the checklist here.

The steps that keep a site migration dull rather than dramatic: what to back up first, how to shift email across without losing a single message, when to touch DNS, and the two mistakes behind nearly every hour of downtime we come across.

One email carrying the checklist, plus the odd bit of hosting advice. Unsubscribe whenever you want: see our privacy policy.

Launch it properly this time.

Every plan includes the essentials others sell as extras — and support that actually answers.

View SSL Certificates plans