To add an SPF record in GoDaddy, open your domain's DNS settings and add a TXT record with the Name set to @ and a value that starts with v=spf1. If there's already a TXT record starting with v=spf1, edit that one instead, because a domain can only have one SPF record and a second one breaks both.
SPF is a DNS record that lists the services allowed to send email for your domain. When your email arrives, the receiving server checks the list. If the server that sent it isn't on the list, your email is more likely to land in junk or be rejected.
Before you start
GoDaddy only controls your DNS if your domain uses GoDaddy's name servers. If someone moved your DNS to your web host or another company, make the change there instead. The record itself is the same.
If you bought Microsoft 365 from GoDaddy and your domain is in the same GoDaddy account, GoDaddy may have added an SPF record for you already. Check before you add anything.
Step 1: Look for an existing SPF record
- Sign in to GoDaddy and open your Domain Portfolio.
- Select your domain, for example yourbusiness.com.au.
- Select DNS to see your DNS records.
- Look through the TXT records for one with the Name @ and a value that starts with v=spf1.
If you find one, you'll edit it in Step 3. If you find two, you'll merge them into one and delete the other.
Step 2: Work out the value you need
An SPF record is one line. It starts with v=spf1, lists each service with an include: entry, and ends with an all rule that tells receivers what to do with everything else.
Microsoft 365 bought directly from Microsoft:
v=spf1 include:spf.protection.outlook.com ~all
Microsoft 365 bought from GoDaddy: GoDaddy tells you to use this, and it already covered Microsoft's servers when we checked:
v=spf1 include:secureserver.net -all
If you have GoDaddy's Advanced Email Security add-on, GoDaddy says to get your value from the Email & Office Dashboard instead.
Microsoft 365 plus another service. Say your website sends enquiry notifications through SendGrid. Add its include to the same record, before the all rule:
v=spf1 include:spf.protection.outlook.com include:sendgrid.net ~all
Use the exact include each service's help pages give you. Some services, including Xero, use their own verification records instead of an SPF include, so follow what the service tells you.
~all or -all? ~all is a soft fail: email from servers not on the list is treated as suspicious. -all is a hard fail: it should be refused. Our reports suggest ~all as a safe starting point. Microsoft and GoDaddy recommend -all once DKIM and DMARC are in place. If your record already ends in -all, keep it. Never use +all, which lets any server in the world send email as you.
Step 3: Edit the record (or add one)
If you found an SPF record in Step 1:
- Select Edit (the pencil icon) next to that record.
- Replace the Value with your new line from Step 2. Keep everything that's still in use and add the new include before the
allrule. - Leave the Name as @ and the TTL as it is.
- Select Save.
If there was no SPF record:
- Select Add New Record.
- Set Type to TXT.
- Set Name to @. Don't type your full domain; GoDaddy adds it for you.
- Paste your line from Step 2 into Value.
- Leave TTL at the default (1 hour).
- Select Save.
If your domain has GoDaddy's Domain Protection, GoDaddy asks for a verification code before it saves the change.
If you found two SPF records, combine every include you still need into one line. Edit one record to hold the combined line, then delete the other.
Step 4: Stay under the 10-lookup limit
Receivers will only do 10 DNS lookups while checking your SPF record. Every include: uses at least one, and some services point to further includes that use more. Go over 10 and receivers treat your SPF record as broken.
From the examples above:
include:spf.protection.outlook.comuses 1 lookup.include:sendgrid.netuses 2.include:secureserver.netuses 3, and already includes Microsoft.
So there's no need to have both secureserver.net and spf.protection.outlook.com in the same record. It only uses up lookups. ip4: entries (a single server address) don't count towards the limit.
If you're close to 10, remove includes for services you no longer use, or ask your provider for a smaller ("flattened") include.
Step 5: Check it worked
GoDaddy says most DNS changes take effect within an hour, but can take up to 48 hours. Once it has had time, send an email from each service you use to your free test address. The report shows whether SPF passed, whether you have more than one SPF record, whether it goes over the 10-lookup limit, and exactly what to change if anything is still wrong.
Common mistakes
- Adding a second SPF record instead of editing the first. This is the most common one.
- Typing the full domain in Name, which can create a record at yourbusiness.com.au.yourbusiness.com.au.
- A space after "include:" or an "=" instead of the colon. It must be
include:spf.protection.outlook.com, with no space. - Putting includes after the
allrule. Receivers stop reading atall, so anything after it is ignored.
Checked against: GoDaddy Help, Add an SPF record · GoDaddy Help, Edit an SPF record · GoDaddy Help, Add an SPF record to my domain for my email (Microsoft 365 from GoDaddy) · Microsoft Learn, Set up SPF to identify valid email sources for your Microsoft 365 domain.