SPF presence

SPF presence comes from public TXT records and shows whether SPF policy material is visible for a domain.

Derived postureMail authenticationPublic TXT evidence

Why it matters

SPF adds mail-posture context

What it adds

Visible SPF configuration is one public signal about sender-authorisation policy when read with MX and DMARC.

What a change may mean

A change may reflect provider migration, sending-service updates, policy tuning or accidental removal.

Limits

Visible SPF is not proof of effectiveness

This view does not recursively evaluate include or redirect chains or test whether SPF is complete or effective.

What .auDO observes

Visible SPF policy material

.auDO derives SPF posture from public TXT evidence. It distinguishes no observed record, a single record, multiple records, malformed material and indeterminate evidence. For a single record it also records the terminal all qualifier.

Technical fields

spf_presentdns_raw.spf_presenttxt_recordsmail-posture/v1

First-order service context

Visible SPF service references

.auDO also shows literal first-order include: and redirect= hostnames. When the Provider Catalogue documents a match, .auDO shows the provider association. This does not change SPF posture.

These are relationship evidence, not a supplier inventory. One domain can show several associations. Unresolved means no documented catalogue match was found.

83 of 98 domains with usable SPF evidence showed at least one first-order include or redirect reference in the 2026-09-10 panel observation.

SPF service references

Documented providers linked from first-order SPF include and redirect targets.

65of 83 target-bearing domains had at least one documented association.

Documented providers seen across 5+ target-bearing domains

  • Amazon Web Services13 of 83 target-bearing domains
  • Campaign Monitor6 of 83 target-bearing domains
  • Google8 of 83 target-bearing domains
  • Mailchimp11 of 83 target-bearing domains
  • Mailgun6 of 83 target-bearing domains
  • Microsoft44 of 83 target-bearing domains
  • Mimecast8 of 83 target-bearing domains
  • Salesforce18 of 83 target-bearing domains
  • SAP5 of 83 target-bearing domains
  • Twilio SendGrid5 of 83 target-bearing domains

Provider counts can overlap because one domain may show several associations. They are not market share.

Evidence and coverage
98usable evidence
83target-bearing domains
65domains with a documented association
56domains with unresolved targets
  • 2 panel domains had insufficient evidence for this role.
  • 15 usable domains had no first-order target for this role.
  • 160 of 275 visible targets matched documented Provider Catalogue associations; 115 remained unresolved.
  • 29 documented providers were visible; 43 target-bearing domains showed more than one.

This does not follow SPF chains, prove every authorised sender, choose a primary provider or establish a supplier relationship.

Observed change

SPF presence change

SPF presence change

Use this signal

See SPF in context

Use Mail trust for the panel view and Cohorts for eligible grouped views.