Do not add multiple SPF records. Add one SPF record and merge Google Workspace, Microsoft 365, and any email tools into that single TXT record. If your domain has two SPF records, receiving mail servers may throw a PermError. That means your legit email can land in spam. Rude, but true.
TLDR: Your domain should have one SPF TXT record, not two or three. For example, if you use Google Workspace and Microsoft 365, combine them like this: v=spf1 include:_spf.google.com include:spf.protection.outlook.com ~all. In a small team of 25 people, one duplicate SPF record can cause sales replies, invoices, and password resets to fail SPF checks for 100% of receivers that enforce the rule strictly. Fixing it usually takes 10 minutes if you can access DNS.
SPF in plain English
SPF stands for Sender Policy Framework. Fancy name. Simple job.
It tells the internet which mail servers are allowed to send email for your domain.
Think of SPF like a guest list at a club.
- Your domain is the club.
- Google Workspace is one approved guest.
- Microsoft 365 is another approved guest.
- Mailchimp, HubSpot, Zendesk, SendGrid may be more guests.
The bouncer wants one clean list. Not five sticky notes. Not a napkin. One list.
If you publish multiple SPF records, the bouncer gets confused. Then your email may get rejected. Or dumped into spam. Honestly, it feels like email systems enjoy punishing tiny mistakes.
The golden rule: one domain, one SPF record
You can add many services to SPF. You just cannot add many SPF records.
This is valid:
v=spf1 include:_spf.google.com include:spf.protection.outlook.com ~all
This is not valid:
v=spf1 include:_spf.google.com ~all
v=spf1 include:spf.protection.outlook.com ~all
Both are TXT records. Both start with v=spf1. That is the problem.
Only one TXT record for SPF should exist at the root domain, such as example.com.
Google Workspace SPF record
If you only use Google Workspace for sending email, your SPF record usually looks like this:
v=spf1 include:_spf.google.com ~all
That says:
v=spf1means this is an SPF record.include:_spf.google.comallows Google servers to send mail.~allmeans soft fail anything else.
Google keeps this pretty simple. You copy the record. You add it at your DNS host. Done.
The annoying part is that people often check the Google Admin console, then try to add another record beside an older one. That breaks things. The better move is to edit the old SPF record.
Microsoft 365 SPF record
If you only use Microsoft 365, your SPF record usually looks like this:
v=spf1 include:spf.protection.outlook.com -all
That says Microsoft 365 is allowed to send mail for your domain. The -all at the end is stricter than ~all.
Here is the tiny drama.
Microsoft may suggest -all. Google docs may show ~all. Your email tool may suggest another version. Now you have three tabs open, two help articles, and a headache.
Use one ending only. Pick the right one for your setup.
~all: Soft fail. Safer when testing.-all: Hard fail. Better after everything is confirmed.?all: Neutral. Usually too weak.
Google Workspace vs Microsoft 365: who manages SPF better?
Neither one truly “manages” SPF for most domains.
Your DNS host manages SPF. That may be GoDaddy, Cloudflare, Namecheap, Squarespace, Wix, Bluehost, or another provider.
Google and Microsoft tell you what to add. Your DNS host is where you add it.
| Feature | Google Workspace | Microsoft 365 |
|---|---|---|
| Basic SPF value | include:_spf.google.com |
include:spf.protection.outlook.com |
| Setup style | Simple guidance in Google Admin | Guided setup in Microsoft 365 admin center |
| Where record lives | Your DNS host | Your DNS host |
| Main risk | Adding Google as a second SPF record | Adding Microsoft as a second SPF record |
Google feels cleaner for basic SPF. Microsoft gives more setup prompts, which helps new admins. But those prompts can also lead to duplicate records if someone clicks too fast.
Expect to waste time on DNS screens that take 30 to 90 seconds to save changes, then another 5 to 30 minutes to update across the internet. Fun? Not really. Normal? Very.
How to combine Google Workspace and Microsoft 365 SPF
Let’s say your domain uses both platforms.
Maybe Google handles normal inboxes. Microsoft handles a legacy app. Or maybe your company is moving from one to the other.
Your combined SPF could be:
v=spf1 include:_spf.google.com include:spf.protection.outlook.com ~all
If you also use SendGrid, it may become:
v=spf1 include:_spf.google.com include:spf.protection.outlook.com include:sendgrid.net ~all
If you use Mailchimp too, add its include if Mailchimp tells you to:
v=spf1 include:_spf.google.com include:spf.protection.outlook.com include:sendgrid.net include:servers.mcsv.net ~all
Keep it clean. Keep it one line. Keep it as one TXT record.
Step by step: add many services to one SPF record
- Find your DNS host. This is where your domain records live.
- Open DNS settings. Look for a section called DNS, zone editor, or domain records.
- Search for TXT records. Find any record that starts with
v=spf1. - Do not create a second SPF record. Edit the existing one.
- Add each service as an include. Put them before the final
~allor-all. - Save the record. Then wait for DNS to update.
- Test it. Use an SPF checker to confirm there is only one SPF record.
Here is the structure:
v=spf1 include:service1.com include:service2.com include:service3.com ~all
Do not put anything after ~all or -all. That ending should be last.
The sneaky SPF limit
SPF has a 10 DNS lookup limit.
This means SPF can only check 10 DNS based items during validation. Includes count. Redirects count. Some other mechanisms count too.
This can bite larger companies.
Example:
- Google Workspace uses lookups.
- Microsoft 365 uses lookups.
- SendGrid uses lookups.
- Mailchimp uses lookups.
- Zendesk uses lookups.
- CRM tools use lookups.
Suddenly, your SPF record looks innocent but fails behind the curtain.
If you hit the limit, remove unused senders. Ask tools if SPF is needed. Some tools can use DKIM instead. You can also use a managed SPF flattening service, but be careful. Bad flattening can age poorly.
Common mistakes that break SPF
- Two SPF records. This is the classic mess.
- Wrong host name. The root domain often uses
@, not the full domain. - Two endings. Never use both
~alland-allin the same record. - Old tools left behind. Remove services you no longer use.
- Copying quotes. Some DNS hosts need quotes. Some add them for you.
- Ignoring subdomains.
example.comandmail.example.comcan have different SPF records.
Which should you use: ~all or -all?
Use ~all while setting things up. It is more forgiving.
Move to -all only after you know every sender is included. That means Google, Microsoft, your support platform, your marketing tool, your billing app, and anything else that sends from your domain.
If you are not sure, stay with ~all for now. A soft fail is better than blocking real mail by accident.
A simple user case
Maya runs a 12 person design studio. Her team uses Google Workspace. Her finance app sends invoices. Her sales tool sends proposals. Then a client asks her to use Microsoft 365 for a shared project mailbox.
Someone adds a second SPF record for Microsoft.
The next day, 18 invoice emails are sent. Six go to spam. Two bounce. One client says, “We never got it.” Great. Now accounting is annoyed.
The fix is not magic. Maya merges the SPF records:
v=spf1 include:_spf.google.com include:spf.protection.outlook.com include:financeapp.example ~all
One record. Three approved senders. Less chaos.
Final rule to remember
Google Workspace plus Microsoft 365 does not mean two SPF records. It means one SPF record with both includes.
Use Google’s include. Use Microsoft’s include. Add other approved senders. Watch the 10 lookup limit. Then test.
Email authentication is picky. But SPF itself is not hard. One guest list. One bouncer. One TXT record.



