Glossary

What Is SPF?

How a single DNS record tells receiving servers which machines may send mail as your domain, and why cold senders need it.

Get your free API key →Free to start. No credit card. 1,000 records to spend whenever you like.

SPF (Sender Policy Framework) is an email authentication standard in which a domain publishes a DNS record listing the servers allowed to send mail for it, so a receiving server can reject or flag mail from anywhere else.

The standard is defined in RFC 7208 (checked September 2026). The receiver looks up the record on the domain in the envelope sender, also called the Return-Path or MAIL FROM address. It then checks whether the connecting IP address is on the list.

Why it matters for outbound

Receivers check SPF before they decide where a cold email lands. A message sent from a server your record does not list fails the check, and it is more likely to go to spam or be refused. Large mailbox providers also publish bulk sender rules that expect authenticated mail.

Every tool that sends for you must be in the record: your mailbox provider, your sequencer, your transactional service. Miss one and that tool's mail fails SPF. Add too many and you hit the limit of 10 DNS lookups in RFC 7208, after which the record returns a permanent error and counts as a failure.

SPF alone is not enough. It checks the envelope address, not the From address the reader sees. DMARC closes that gap by requiring domain alignment between the two, and it passes when SPF or DKIM passes and aligns.

Example

You send from jane@acme.com through Google Workspace and a sequencer. You publish one TXT record on acme.com. The values are placeholders.

code
acme.com  TXT  "v=spf1 include:_spf.google.com include:sequencer.example ip4:203.0.113.10 -all"

Read it left to right:

  • v=spf1 marks the record as SPF version 1.
  • include: pulls in another sender's approved servers. Each one costs lookups.
  • ip4: allows a single address you run yourself. It costs no lookup.
  • -all says fail everything not listed. ~all is the softer version that marks it as a soft fail.

A domain may publish only one SPF record. Two records are a permanent error, so merge them into one line.

In LeadOcean data

LeadOcean has no SPF field, filter or endpoint. SPF is a property of your own sending domain, not of the people or companies in the dataset, so you set it up in your mail provider and your DNS.

What LeadOcean does cover is the recipient side. Every person record carries email_status, and /v1/people/search accepts an emailStatus filter, so you can mail only addresses that were verified (openapi.json, September 2026). A passing SPF record does not rescue a list full of bounces.

For the three standards together, read DMARC, SPF and DKIM explained. For the DNS steps, see the SPF record setup guide. Pricing is on /pricing. More terms are in the glossary.

Pair an authenticated domain with emails that are already verified

Free to start. No credit card. 1,000 records to spend whenever you like.

Get your free API key →