Add an SPF record
spf-missing
With no SPF record any server can send mail claiming to be your domain, and receivers have nothing to check it against. Publish one TXT record.
Why this matters
Your email authentication isn't fully enforcing who can send on your behalf, so mail servers can't reliably block unauthorized senders. Whether that's exploitable depends on your DMARC policy.
CDN and edge
Cloudflare
- 1 Go to DNS > Records
- 2 Add a TXT record for your domain with your SPF policy
- 3 Include your email provider's servers
Type: TXT
Name: @
Content: v=spf1 include:_spf.google.com ~all
# Adjust 'include:' for your email provider:
# Google: include:_spf.google.com
# Microsoft: include:spf.protection.outlook.com
# SendGrid: include:sendgrid.netDoes your app still have this?
Scan your domain