What does an SPF record do for cold email?
An SPF record lists the servers allowed to send email as your domain. A receiving server reads it, checks the sending server against it, and treats mail from anywhere else as suspect. Without one, a cold email from a new domain has nothing vouching for it. Our SPF record guide explains every part of the syntax.
Which mail host should I tick for a cold email domain?
The one your sending mailboxes live on: Google Workspace or Microsoft 365 for most cold email setups. Bulk email services such as newsletter platforms usually send with their own return-path domain, which is what SPF actually checks, so adding them to your record only uses up lookups. Add a service only if its own setup page tells you to.
Why does a cold email SPF record have a 10-lookup limit?
RFC 7208 caps an SPF check at 10 DNS lookups. Every include, a, mx and exists costs one, and includes can contain more includes. Go over 10 and receivers return a permanent error, which fails SPF for every email. A sending domain used only for cold email rarely needs more than one include.
Should a cold email domain use ~all or -all?
Start with ~all. It marks unlisted senders as suspicious without telling receivers to bounce them, which is forgiving while you are still finding every service that sends for you. Move to -all once your DMARC reports show nothing legitimate failing.
Where do I put the SPF record for a cold email domain?
Add a TXT record at the root of the domain (host @) in your DNS provider. A domain must have exactly one SPF record: if one exists already, edit it rather than adding a second, because two records count as an error. Then run the domain checker to confirm it resolves.