Guide per DNS host

Add an SPF record at ALL-INKL

ALL-INKL hosts mailboxes and DNS, so there is a fixed SPF value when mail is only sent through ALL-INKL. This guide shows the value, the way to the DNS editor and the mistakes that happen most often at ALL-INKL.

The SPF value for ALL-INKL

ALL-INKL shows the matching SPF value in the email settings of the control panel. If the domain only sends through the ALL-INKL mail servers that are also listed as MX, the mx mechanism is enough: every server receiving mail for the domain may also send.

v=spf1 mx -all

When other services send as well

A newsletter tool, CRM, ticket system or Microsoft 365 alongside the ALL-INKL mailboxes: every service goes into the same record as its own include. There must be only one TXT record with v=spf1; a second one invalidates both. At most ten DNS lookups are allowed, Google Workspace costs four, Microsoft 365 two, most newsletter tools one or two.

v=spf1 mx include:spf.protection.outlook.com include:spf.brevo.com -all

How to add the SPF record at ALL-INKL

The way to the ALL-INKL DNS editor:

  • Sign in to KAS (the customer administration system) and open "Domain".
  • Click "edit" next to the domain and then "DNS settings".
  • "Create new DNS record", enter name (empty for the apex), type and value, save.
  • Type TXT, host name @ (at some hosts leave empty or pick the domain name), value: the full SPF record starting with v=spf1. If a TXT record with v=spf1 already exists, edit it rather than adding a second one.
  • ALL-INKL applies changes within minutes.

Typical mistakes at ALL-INKL

  • Two TXT records with v=spf1: both are ignored. Always edit the existing one.
  • The record sits on www or a subdomain instead of the apex domain.
  • Quotation marks typed into the value: the DNS editor adds them itself.
  • More than ten lookups after adding further services.

Verify and keep an eye on it

After saving, the change at ALL-INKL usually applies within minutes. The checker below queries the authoritative name servers and shows right away whether the SPF record is read correctly. DomainWarn keeps checking the record afterwards and alerts you when it changes or disappears, for example after a migration or one click too many in the DNS editor.

Frequently asked questions

Where do I find the SPF value in the ALL-INKL control panel?
In the email settings of the domain; ALL-INKL shows the recommended value there. If only ALL-INKL sends, that value is enough.
How long until the SPF record takes effect?
At ALL-INKL usually minutes, at the latest once the TTL of the old record has expired. Receivers query the record with every message.
Check now

Free SPF record check and lookup: syntax, includes, the 10 DNS lookup limit and the closing qualifier. Shows whether your domain blocks forged senders.

DomainWarn checks SPF, DKIM, DMARC, DNS and certificates of all client domains regularly and reports changes before mail lands in spam.

Monitor this domain continuously14-day free trial, no credit card.

The same guide for other hosts