Inventory sending before writing policy
SPF lets a domain publish which infrastructure may send mail using a particular envelope identity. It does not encrypt email, authenticate every visible sender field or prevent all impersonation. A good record reflects actual authorised senders rather than an internet example pasted into DNS.
Start with your normal email provider, website forms, invoicing tools and any other approved service that sends using the domain. Receiving mail through a service is not automatically evidence that it needs sending authorisation.
Prepare a controlled change
- Read the domain's current TXT records and identify the existing SPF policy. Save its value and TTL privately before editing. Avoid adding a second competing SPF record at the same owner name.
- Ask each authorised sending service for its current SPF instructions. Record the domain identity it actually uses; a service may send with its own envelope domain rather than yours.
- Build one policy containing the necessary supported mechanisms. Check the SPF DNS-lookup limit and the effects of nested includes. A short-looking record can still trigger many lookups.
- Review the final policy with the mail administrator and change it during a suitable window. Choose the ending policy based on the validated inventory, not on a desire to obtain the strictest-looking score immediately.
Verify the published value
Query the relevant TXT record after the change and compare with the intended value. Allow for recursive caching according to the previous TTL; a single cached answer does not prove that publication failed. Then send harmless tests from each approved service to a mailbox you control and inspect the receiving system's authentication results.
Investigate failures precisely
A forwarded message may behave differently from direct delivery. An SPF pass also does not necessarily give DMARC alignment if the authenticated envelope domain differs from the visible From domain. Keep the identity and delivery path in your notes.
Avoid authorising the whole internet
Do not use broad mechanisms or copy unknown includes simply to silence delivery failures. Each addition should have an identified owner and business purpose. If a retired service remains authorised, remove it after confirming it no longer sends legitimate messages. Maintain the sender inventory whenever billing, marketing or website tooling changes.
Official references
Consult the current vendor documentation if your version or screen differs.
Documentation-based draft. Commands have not all been executed against the named products in a lab. Validate configuration examples against your installed version before changing a working system.