SPF Configiration


SPF Helps Prevent Your Domain from Being Spoofed. It is an important tool to protect your email internally and externally.
The full name is Sender Policy Framework, and is designed to ensure that the Sender of a message is who they claim to be.

To implement SPF, follow these 3 steps. Our estimated time is about one hour to have SPF enabled for your domain.

1. Generate an SPF records
SPF records are entries for your Domain in DNS. For example, Maysoft.com has spf set. Here is our SPF Record:

v=spf1 mx a ip4:199.103.5.118 +ip4:208.85.190.140 +ip4:208.85.190.141 +ip4:199.103.5.142 +ip4:199.103.5.143 +ip4:199.103.5.99 +ip4:199.103.5.74 +ip4:208.85.190.76 +ip4:208.85.188.119 include:spf.protection.outlook.com include:spf.em.secureserver.net -all

It looks scary, but it is simply a list of approved servers that can send mail for our domain. Don't overlook multiple servers or mail senders that send mail on your behalf (e.g. ConstantContact). In our case, Maysoft.com has MS365 mail, so we have included spf.protection.outlook.com to tell mail recipients that these messages are legitimately from maysoft.com


Here is a tool we use to build this string:
https://mxtoolbox.com/SPFRecordGenerator.aspx


Here is an alternate tool:
https://www.spfwizard.net/


You can always check the generated SPF syntax independently using this tool:
https://vamsoft.com/support/tools/spf-syntax-validator



2. Publish your SPF Record on your Domain

SPF Records are stored with your domain name provider (who you use to manage your domain), like Network Solutions or GoDaddy. They have an easy way to take your completed SPF record and make it available to show all people who receive your mail if it really originated from one of your servers, or an external approved mailer.

Here is how to update your domain with the TXT record (your SPF record).

Here are instructions on how to do that for NetworkSolutions.com
https://www.mail-tester.com/spf/network-solutions#access-dns-manager

Here are instructions on how to do that for GoDaddy.com
https://www.godaddy.com/help/add-an-spf-record-19218



3. Check your SPF Record

You can check your syntax and see if an IP address is allowed to send for your domain (or any other) here:

https://vamsoft.com/support/tools/spf-policy-tester


Here is a check of the Maysoft.com SPF record

https://mxtoolbox.com/SuperTool.aspx?action=spf%3amaysoft.com&run=toolpage



Once these steps are complete, it becomes much harder for others to spoof mail from your domain, and SpamSentinel can stop all senders who spoof your domain from sending messages internally to users.

Contact Information
If you have any questions about this document, or want help setting up SPF for your domain, please contact us at support@maysoft.com


( domino-web.maysoft.com )

( domino-web.maysoft.com )