Good practice: Recommended as good practice. Not required.National Cyber Security Centre (NCSC), good practice

SPF record for your school email domain

An SPF record in your domain's DNS lists every service allowed to send email for your school, which helps stop spoofed emails.

Check this on my website

Who it applies to

Published on
School and trust websites
School type
Academies and maintained schools
School stage
All stages, from early years to sixth form
Does not apply to
No school types are excluded

When it's due

Keep it up to date

There's no fixed date. Update it whenever something changes.

What's needed

Set up an SPF record in the DNS for your school's or trust's email domain, listing every service that sends email for it, within 10 domain lookups and 450 characters.

What it must contain

3 parts
  • Keeps the SPF record within 10 domain lookupsGood practice: Recommended as good practice. Not required.
  • Has an SPF record listing every address the school sends email fromGood practice: Recommended as good practice. Not required.
  • Keeps the SPF record to 450 characters or fewerGood practice: Recommended as good practice. Not required.

What the official sources say

Set out in 2 official sources:

NCSC: create and iterate an SPF record

Version 2026-09-13

  • Create an SPF record in your public DNS, using all the IP addresses or address ranges from which you send email. You can use both IPv4 and IPv6 addresses.

    Good practice: Recommended as good practice. Not required.§ Page 8 of 14 > Create and iterate an SPF record > Create an SPF record

  • SPF works by providing domain owners a way to publish a list of the IP addresses which should be trusted for a given domain. A receiving email service can then check that a sending email service has an IP address which appears in the sender's published list.

    Good practice: Recommended as good practice. Not required.§ Page 8 of 14 > Create and iterate an SPF record (introduction)

Show 3 more from this source
  • The SPF protocol limits the size of its record to 450 bytes (ie characters) or fewer. If your software does not provide a character count, which should include spaces, we recommend you search online for 'character counter' and confirm that your proposed SPF record is 450 bytes or fewer.

    Good practice: Recommended as good practice. Not required.§ Page 8 of 14 > Understanding and overcoming SPF limitations > SPF record size limit of 450 bytes or fewer

  • The SPF protocol has some built-in protection – it protects receiving mail servers from denial of service attack by limiting the number of domain lookups to 10.

    Good practice: Recommended as good practice. Not required.§ Page 8 of 14 > Understanding and overcoming SPF limitations > DNS lookup restrictions

  • SPF syntax is very sensitive to white space. This is one of the most common causes of errors in SPF records. In particular, the failure to put a spaces between the SPF terms (eg between IP addresses).

    Good practice: Recommended as good practice. Not required.§ Page 8 of 14 > SPF Errors

Email security and anti-spoofing (SPF, DKIM, DMARC)

Version 2026-09-13

  • Sender Policy Framework (SPF) allows you to publish IP addresses which should be trusted for your domain.

    Good practice: Recommended as good practice. Not required.§ Page 1 of 14 > introduction, point 1 (In summary)

  • Domain-based Message Authentication, Reporting and Conformance (DMARC) allows you to set a policy for how receiving email servers should handle email which doesn’t pass either SPF or DKIM checks. This includes untrusted emails, which should be discarded. DMARC also generates reports, which you can use to understand how your email is being handled.

    Good practice: Recommended as good practice. Not required.§ Page 1 of 14 > introduction, point 1 (In summary)

Show 1 more from this source
  • Domain Keys Identified Mail (DKIM) allows you to cryptographically sign email you send to show it’s from your domain. Although DKIM is not as widely supported as SPF, it has the advantage of being able to support forwarded email.

    Good practice: Recommended as good practice. Not required.§ Page 1 of 14 > introduction, point 1 (In summary)

Questions schools ask

Do schools need an SPF record?

For academies and maintained schools, it's recommended as good practice, not required.

What does an SPF record need to include?

Keeps the SPF record within 10 domain lookups; Has an SPF record listing every address the school sends email from; Keeps the SPF record to 450 characters or fewer.

When do we need to update our SPF record?

Keep it up to date. There's no fixed date. Update it whenever something changes.

Where does the requirement for the SPF email record come from?

It is set out in NCSC: create and iterate an SPF record and Email security and anti-spoofing (SPF, DKIM, DMARC).

Recent changes to the official guidance

The official sources for this requirement don't publish dated change notes. We check them for changes ourselves.

We last checked these sources on 21 September 2026.

Get an email when the requirements change

The DfE updates what schools must publish most years. We'll tell you what changed.

A few emails a year. Unsubscribe at any time. Privacy notice

Is this on your school's website?

Enter your school email address and we'll check your website for this requirement.

It's free, and the result arrives by email.

We email the result here. Privacy notice

Free: up to 3 single checks a year. Paid: every requirement, audited every month. See prices →

Or audit your whole website for free →

Official sources last checked 21 September 2026 · register version 1.0.4