Manage your SPF senders from a list, behind one include.
We serve your SPF record behind one include: every sender's current addresses written out as plain ranges and re-resolved every hour. Your record spends one DNS lookup on us, and you add or remove a sender on the domain's page.
Create your account Count your lookups first
Imports the record you publish today · Refreshed every hour · Leave with your record written out
Setup replaces your includes with one
Most SPF records are a list of includes, one per provider, each spending lookups against the limit of ten. Past ten, receivers read the record as broken.
Switch to hosted SPF
On the domain's SPF page, press Switch to hosted SPF. We read the record you publish and import it sender by sender. A record we can't keep whole is refused, with the reason.
Publish one include
Replace the includes in your apex record with the one we give you. Your
own ending stays: ~all or -all is still your call.
Manage senders on the page
Pick a provider from the catalogue or type any mechanism. The served record carries the change within the minute. Removing one is the same button in the other direction.
The addresses refresh on their own
Providers renumber without telling you, which is why a hand-flattened record rots. Ours is re-resolved every hour and the changes are written down.
One lookup for the include
Behind the include we publish literal ip4 and
ip6 terms. A receiver spends one lookup on your include and reads
plain addresses behind it. A list too long for one record chains a second one, and
the meter on the page counts every lookup the served record costs.
Refreshed every hour
We re-resolve every sender's published ranges each hour and publish what we find. An edit to the list applies straight away.
How much mail each sender actually sends
Each row shows what your DMARC reports say about it: how much mail matched its addresses over the last 30 days, and whether that mail passed SPF. A sender that sent nothing in 30 days shows up as exactly that.
Every change is in the digest
The Monday digest lists every change to the served record. A switch on the account page adds a same-day mail for each refresh that changed the addresses.
A big drop in addresses waits for your OK
A scheduled refresh that would drop a large share of the served addresses is held, because that shape is usually a provider's DNS answering incompletely. We email you the day it happens. One press of Refresh senders applies it when the shrink is real.
You keep your own ending
The include is one term in a record you still own. The
~all or -all you publish tells receivers what to do with
mail from an address outside the list.
What happens when a refresh fails
A refresh that fails publishes nothing
The last good ranges keep serving and your mail keeps flowing. We email you when a failure stands for a day, so a provider whose DNS has been broken since Tuesday is a message in your inbox and a note on the card.
If our DNS is unreachable
Receivers defer your mail with a temporary error and retry. Mail bounces only if the outage holds for longer than their retries. If your plan lapses, the record keeps serving and its addresses keep refreshing. Only the sender controls lock.
Stop hosting and we write the record out for you
Press Stop hosting and the page writes a self-managed record built from your
sender list, ready to publish at your apex. It ends in ~all. Swap in
-all if that is what your record ended with. We keep answering
the include until your published record stops referencing us, and for twenty days after
that, so every sender keeps its pass across both edits.
Part of Pro and Team
Hosted SPF comes with the paid plans, beside the monitoring they're built on: the Monday digest, same-day alerts, and the sender evidence behind every verdict. Pro watches 5 domains for $19 a month and Team watches 25 for $79. Every paid feature is free for 14 days, no card.
Where to go next
Questions people ask first
Is this SPF flattening?
Yes, done on a schedule and served from our zone, so the flattened record never goes stale in your DNS. You keep a list of senders. We keep their addresses current.
What happens to the ten-lookup limit?
Your record spends one lookup on our include. Behind it the addresses are literal, so reading them costs nothing. A list too long for one record chains a second one behind the first, and the meter on the page counts every lookup the served record costs.
What if a provider changes its addresses?
We re-resolve every sender each hour and publish the new ranges. The Monday digest lists the change. A same-day mail does too, if you've switched that on for the account.
Does hosted SPF need hosted DMARC?
No. Each hosted service is its own switch on the domain's page. A domain can host SPF alone and keep its DMARC record wherever it lives today.
What happens if DomainCanary is down?
Receivers that can't resolve the include defer your mail with a temporary error and retry. Mail bounces only if the outage holds for longer than their retries.
Can I keep other mechanisms in my own record?
Yes. The include is one term in a record you still own. Keep an ip4 for the office mail server beside it if you like, and keep your own ending. The meter on the page counts what we serve. Anything you keep beside the include in your own record adds to it.
How do I leave?
Press Stop hosting and the page writes out a record built from your sender list, ready to publish at your apex. We keep answering the include until your record stops referencing us, and for twenty days after that.
What does it cost?
It's part of Pro and Team. Pro watches 5 domains for $19 a month and Team watches 25 for $79. Every paid feature is free for 14 days, and the trial needs no card.
Add the next sender from a page
Enabling imports the record you publish today, sender by sender. From then on the list lives on the domain's page and the addresses behind it refresh on their own.
First domain free · 14 days of every paid feature · No card
- One include at your apex, your own ending kept
- Every sender's addresses re-resolved each hour
- A failed refresh publishes nothing and mails you
- Per-sender traffic from your own DMARC reports