SPF (Sender Policy Framework)

SPF (Sender Policy Framework) is a method with which a domain specifies which mail servers are allowed to send emails on its behalf. Receiving systems can thus check whether a message was sent from an authorized system or whether it could be a spoofing attempt.

SPF is implemented via a TXT record in the DNS of the domain that lists the authorized IP addresses and sending systems. Receiving mail servers compare the delivering IP address against this record and assess the result (pass, fail, softfail). A well-known limitation: with forwarding, the SPF check frequently breaks, because the forwarding infrastructure is not authorized – one reason why SPF alone is not sufficient.

Only in interaction with DKIM and DMARC does a resilient protection model against sender spoofing and delivery problems emerge. For organizations, SPF is relevant because misconfigurations can have a direct impact on security, brand trust and the deliverability of legitimate emails.