<!-- Set Up an SPF Record on Cloudflare — https://docs.warmerly.com/guides/spf/cloudflare -->

# Set Up an SPF Record on Cloudflare

An **SPF record** is a single TXT record that lists which mail servers may send email for your domain. This guide shows exactly where to add it in Cloudflare. If you want the background first, read [What Are SPF & DMARC?](https://docs.warmerly.com/guides/spf-dmarc).

## What you'll need

- The SPF **include** value from your email provider. For Google Workspace it is `include:_spf.google.com`; for Microsoft 365 it is `include:spf.protection.outlook.com`. Check your provider's help page for the exact value if you use another service.
- Access to the domain's DNS in Cloudflare.

## Step 1: Open your domain's DNS in Cloudflare

1. Go to [dash.cloudflare.com](https://dash.cloudflare.com) and sign in.
2. Click the domain you send email from.
3. In the left-hand menu, click **DNS**, then **Records**.

## Step 2: Add the SPF TXT record

1. Click **Add record** and choose **TXT** as the type.
2. In the **Name** field: Enter `@` (this means the root domain, `yourdomain.com`). Some panels leave the field blank for the root instead. Never type the full domain name here.
3. In the **Content** field: Paste your SPF value, for example `v=spf1 include:_spf.google.com ~all`.
4. Leave **TTL** on **Auto**. TXT records are never proxied, so there is no orange-cloud setting to change.
5. Click **Save**.

| Field | What to enter |
| --- | --- |
| Type | `TXT` |
| Name | `@` |
| Content | `v=spf1 include:_spf.google.com ~all` |

## If you already have an SPF record

A domain can only have **one** SPF record. If Cloudflare already shows a TXT record starting with `v=spf1`, **edit that record** and add your new `include:` before the `~all` at the end. Adding a second SPF record breaks SPF for the whole domain, so mail starts failing authentication.

For example, to send from Google Workspace and another tool, combine them into one record:

```
v=spf1 include:_spf.google.com include:spf.mailprovider.com ~all
```

SPF also allows at most 10 DNS lookups across all your `include:` entries. If you go over, SPF fails with a "permerror".

## Step 3: Check SPF in Warmerly

Warmerly rechecks your domain's DNS automatically. DNS changes can take anywhere from a few minutes up to 24 to 48 hours to spread, so if the SPF warning is still showing right after you save, check again later. You do not need a selector for SPF, because it is one record at a fixed location.

## Still stuck?

Back to the main guide: [What Are SPF & DMARC?](https://docs.warmerly.com/guides/spf-dmarc). The same click-path in Cloudflare is used for [DKIM](https://docs.warmerly.com/guides/dkim/cloudflare). To see what is live right now, use the free [SPF checker](https://warmerly.com/spf-checker) or [DMARC checker](https://warmerly.com/dmarc-checker).
