Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

Use SPF include: to authorize a separately administered sender while keeping your domain’s own SPF policy. Use redirect= when domains under the same administrative control should share a complete SPF policy, and the current record should defer to that policy only if none of its mechanisms matches.

The distinction matters: include: is a mechanism evaluated in sequence; redirect= is a fallback modifier. Both can consume the SPF DNS lookup budget.

How SPF include: and redirect= differ

SPF checks a domain’s published policy to determine whether a sending host is authorized. The two directives can both refer evaluation to another domain, but they do not do the same job. RFC 7208 defines include: as a mechanism and redirect= as a modifier. RFC 7208, Sections 4.6.4, 5.2 and 6.1, published by the IETF in April 2014, sets out their evaluation rules.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Decision point include: redirect=
Role in SPF Mechanism Modifier
When it runs At its position in the ordered record After local mechanisms fail to match
What happens next The referenced policy is evaluated; its result determines whether the include mechanism matches, and a non-match resumes the original record Evaluation proceeds using the target domain’s policy
Typical policy relationship Authorizes a separately administered sender while retaining the original domain’s policy Shares a complete policy among domains under common administrative control
Effect of an all mechanism Can be evaluated if it appears earlier in the record Any all mechanism matches, so the redirect is ignored
DNS lookup budget Can trigger DNS queries, including nested evaluation Can trigger DNS queries, including nested evaluation

When to use include:

Use include: when your domain needs to authorize a sender whose SPF policy is maintained by another administrative party, but you also need your own policy to continue after the referenced policy does not match. The include mechanism evaluates the target domain’s SPF record; it does not paste that record’s mechanisms into yours.

A match in the referenced policy makes the include: mechanism match. If the referenced policy does not match, evaluation continues at the next mechanism in your original record. In particular, a -all in the included record is not automatically a stop instruction for the calling record. RFC 7208 notes that the name “include” can be misleading for this reason.

Illustrative pattern

v=spf1 include:service.example -all

This is a syntax illustration from RFC 7208, not a checked or live DNS record. Confirm the sender’s actual SPF policy and the complete nested lookup chain before using a target domain.

When to use redirect=

Use redirect= when a domain should rely on another domain’s complete SPF policy after none of its own mechanisms matches. RFC 7208 generally favors redirect for sharing authorization and policy within one administrative authority. It may be a poor fit across administrative boundaries: the target policy can behave unexpectedly when it uses sender-dependent macros, so check compatibility rather than assuming an external provider’s policy can be used as a fallback.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Illustrative pattern

v=spf1 redirect=_spf.example.com

This is a structural example, not a live record. The target must publish an appropriate SPF policy, and the whole evaluation must remain within the DNS lookup limit.

Why all changes the result

An all mechanism always matches. If the current record contains one, SPF reaches that match instead of falling through to the redirect, regardless of where the redirect modifier appears. So redirect= is not a fallback when an all mechanism is present.

Does redirect= count toward the 10-lookup limit?

Yes. SPF evaluation must limit the total number of DNS-query-causing terms to 10. The count includes include, redirect, a, mx, ptr and exists terms encountered during the evaluation. If the limit is exceeded, the result must be permerror (RFC 7208 §4.6.4).

Count the nested policy chain, not only the terms visible in the first record. An include: or redirect= can lead to further DNS-query-causing terms in the referenced policy. The limit is per SPF evaluation; it is not a separate allowance for each record.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Five SPF mistakes to avoid

  1. Assuming include: merges records. It evaluates the referenced policy and uses its result; it does not insert the target’s mechanisms into the caller’s record. A non-match resumes the caller’s evaluation.
  2. Adding all and expecting a redirect fallback. Because all always matches, a record containing it does not reach redirect=.
  3. Redirecting across administrative boundaries without checking the target policy. A target that uses sender-dependent macros may not work reliably for another domain. For a separately administered sender, include: is generally the more suitable pattern.
  4. Counting only top-level terms. Nested evaluation can push the total over 10 DNS-query-causing terms and produce permerror.
  5. Duplicating or misplacing redirect=. RFC 7208 says the modifier must not appear more than once and should appear last. A duplicate causes permerror.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Publish and finish the SPF policy deliberately

RFC 7208 requires SPF records to be published as DNS TXT records. It recommends making the policy’s ending explicit with all or redirect=; without either, a no-match result is neutral. Choose an ending that fits the policy: do not add all to a record intended to fall through to a redirect.

The examples above show syntax only. Before publishing, verify that the chosen target’s policy matches your administrative arrangement and that the full DNS evaluation stays within the specified limit.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.