Skip to main content
SecurityFreeBy Daniel BeglaryanUpdated August 2026

SPF, DKIM & DMARC Generator

Build SPF, DKIM, and DMARC records with guided forms and copy-ready DNS output.

PrivateWorks OfflineNo Account

Everything is built in your browser

Nothing you type is sent anywhere. This generates the record text — it doesn’t read or change your live DNS. Paste the result into your DNS provider, then verify with a lookup tool afterward.

Only used to show the full record name. Leave blank to see the short host most dashboards want.

SPF — who is allowed to send

SPF (Sender Policy Framework) lists the servers permitted to send email for your domain. It lives on the domain root (@) as a single TXT record.

Adds each provider’s official include. Pick every service that sends mail as your domain.

Any additional include domains, one per line or space-separated (e.g. spf.example.com). The include: prefix is added for you.

Individual IPs or CIDR ranges. Separate with spaces, commas, or new lines.

IPv6 addresses or ranges, same formatting.

Authorize the hosts already in your A / MX records to send too. Each of these costs one of your 10 SPF lookups.

How receivers should treat mail from a server that isn’t listed above. Start at ~all while you confirm nothing legitimate is missing, then tighten to -all.

DNS lookups used: 1 / 10

Your DNS record
Type
TXT
Host / Name
@
TTL
3600 (1 hour)
Value
v=spf1 include:_spf.google.com ~all
Deep dive

About SPF, DKIM & DMARC Generator.

Generate SPF, DKIM, and DMARC Records the Right Way

Email authentication is three DNS records working together: SPF says which servers may send for your domain, DKIM publishes the public key that verifies your signature, and DMARC ties them together and tells receivers what to do with mail that fails. This tool builds all three from plain-language forms, so you get valid, correctly-formatted TXT records without memorizing the syntax.

Every field is explained as you fill it in, and the output is a ready-to-paste record with the exact host and value your DNS provider asks for — plus live warnings for the mistakes that quietly break deliverability, like passing SPF's 10-lookup limit or enforcing DMARC with nowhere to send the reports.

Two honest limits: it writes the record text, it does not read or change your live DNS, so paste the result into your provider and confirm it with a lookup afterward. And it never touches private keys — DKIM key pairs are generated by your email provider, and you paste only the public half here.

Common Uses

  • New domain setup: Add SPF, DKIM, and DMARC before your first campaign so mail lands in the inbox instead of spam.
  • Multiple senders: Combine Google Workspace, a marketing platform, and a transactional service into one valid SPF record — and watch the lookup counter stay under 10.
  • DMARC rollout: Start at p=none with reporting, then step through quarantine to reject using the pct field, without hand-editing tags.
  • Fixing failures: Rebuild a malformed record that a mail tester flagged, with the correct qualifier, alignment, and syntax.
  • Client handoffs: Produce clean, documented records for a customer's domain that any DNS dashboard will accept.

Privacy: Every record is assembled entirely in your browser with client-side JavaScript. Your domain, keys, and report addresses are never uploaded, logged, or sent to any server.

Three steps

How to use SPF, DKIM & DMARC Generator.

01

Upload your file

Drag and drop or click to select your file.

02

Choose settings

Adjust quality, size, or format options.

03

Download result

Your processed file is ready instantly.

More in Security

Related security tools.

Why CipherForces

Privacy-first tools that work everywhere.

100% Private
From $39
Works Offline
No Account
188 Tools

Need more than a tool?

One team for your website, print, automation & branding — websites from $799.

Explore all 188 tools