SPF record for your school email domain
An SPF record in your domain's DNS lists every service allowed to send email for your school, which helps stop spoofed emails.
Check this on my websiteWho it applies to
- Published on
- School and trust websites
- School type
- Academies and maintained schools
- School stage
- All stages, from early years to sixth form
- Does not apply to
- No school types are excluded
When it's due
Keep it up to date
There's no fixed date. Update it whenever something changes.
What's needed
Set up an SPF record in the DNS for your school's or trust's email domain, listing every service that sends email for it, within 10 domain lookups and 450 characters.
What it must contain
3 parts- Keeps the SPF record within 10 domain lookupsGood practice: Recommended as good practice. Not required.
- Has an SPF record listing every address the school sends email fromGood practice: Recommended as good practice. Not required.
- Keeps the SPF record to 450 characters or fewerGood practice: Recommended as good practice. Not required.
What the official sources say
Set out in 2 official sources:
NCSC: create and iterate an SPF record
Create an SPF record in your public DNS, using all the IP addresses or address ranges from which you send email. You can use both IPv4 and IPv6 addresses.
Good practice: Recommended as good practice. Not required.§ Page 8 of 14 > Create and iterate an SPF record > Create an SPF record
SPF works by providing domain owners a way to publish a list of the IP addresses which should be trusted for a given domain. A receiving email service can then check that a sending email service has an IP address which appears in the sender's published list.
Good practice: Recommended as good practice. Not required.§ Page 8 of 14 > Create and iterate an SPF record (introduction)
Show 3 more from this source
The SPF protocol limits the size of its record to 450 bytes (ie characters) or fewer. If your software does not provide a character count, which should include spaces, we recommend you search online for 'character counter' and confirm that your proposed SPF record is 450 bytes or fewer.
Good practice: Recommended as good practice. Not required.§ Page 8 of 14 > Understanding and overcoming SPF limitations > SPF record size limit of 450 bytes or fewer
The SPF protocol has some built-in protection – it protects receiving mail servers from denial of service attack by limiting the number of domain lookups to 10.
Good practice: Recommended as good practice. Not required.§ Page 8 of 14 > Understanding and overcoming SPF limitations > DNS lookup restrictions
SPF syntax is very sensitive to white space. This is one of the most common causes of errors in SPF records. In particular, the failure to put a spaces between the SPF terms (eg between IP addresses).
Good practice: Recommended as good practice. Not required.§ Page 8 of 14 > SPF Errors
Email security and anti-spoofing (SPF, DKIM, DMARC)
Sender Policy Framework (SPF) allows you to publish IP addresses which should be trusted for your domain.
Good practice: Recommended as good practice. Not required.§ Page 1 of 14 > introduction, point 1 (In summary)
Domain-based Message Authentication, Reporting and Conformance (DMARC) allows you to set a policy for how receiving email servers should handle email which doesn’t pass either SPF or DKIM checks. This includes untrusted emails, which should be discarded. DMARC also generates reports, which you can use to understand how your email is being handled.
Good practice: Recommended as good practice. Not required.§ Page 1 of 14 > introduction, point 1 (In summary)
Show 1 more from this source
Domain Keys Identified Mail (DKIM) allows you to cryptographically sign email you send to show it’s from your domain. Although DKIM is not as widely supported as SPF, it has the advantage of being able to support forwarded email.
Good practice: Recommended as good practice. Not required.§ Page 1 of 14 > introduction, point 1 (In summary)
Questions schools ask
Do schools need an SPF record?
For academies and maintained schools, it's recommended as good practice, not required.
What does an SPF record need to include?
Keeps the SPF record within 10 domain lookups; Has an SPF record listing every address the school sends email from; Keeps the SPF record to 450 characters or fewer.
When do we need to update our SPF record?
Keep it up to date. There's no fixed date. Update it whenever something changes.
Where does the requirement for the SPF email record come from?
It is set out in NCSC: create and iterate an SPF record and Email security and anti-spoofing (SPF, DKIM, DMARC).
Recent changes to the official guidance
The official sources for this requirement don't publish dated change notes. We check them for changes ourselves.
We last checked these sources on 21 September 2026.
Is this on your school's website?
Enter your school email address and we'll check your website for this requirement.
It's free, and the result arrives by email.
Official sources last checked 21 September 2026 · register version 1.0.4