Cloudflare SPF record
Cloudflare is usually where your SPF record lives (as a DNS host) rather than a sender. Cloudflare Email Routing adds _spf.mx.cloudflare.net; otherwise you are just publishing your TXT record on Cloudflare’s DNS.
The SPF include for Cloudflare
Authorize Cloudflare by adding its mechanism to your single SPF TXT record:
v=spf1 include:_spf.mx.cloudflare.net ~all
Approximate lookup cost: 1 DNS lookup(s). Remember you have a budget of 10 total across every sender in the record.
Provider include values change occasionally. Confirm the current value in your
Cloudflare admin console before publishing, and never create a second
v=spf1 record — a domain may have only one.
Combine all senders into one record:
v=spf1 include:spf.protection.outlook.com include:_spf.mx.cloudflare.net ~all
Note on “Cloudflare SPF flattening”: Cloudflare DNS does not flatten SPF records for you automatically. You can host a flattened or macro-based record on Cloudflare, but keeping it in sync as providers change IPs is on you — which is precisely what a managed flattening service handles.
When adding Cloudflare pushes you over the limit
Every include you stack — your mailbox provider, this one, a marketing tool, a
help desk — adds to the same 10-lookup budget. The moment recursive expansion crosses
10, receivers return permerror and your SPF stops
passing. You cannot shrink the nested provider records, so the durable fix is to
flatten the record or move to a
single-lookup macro that stays in sync automatically.
Frequently asked questions
What is the SPF include for Cloudflare?
include:_spf.mx.cloudflare.net to your single SPF record, e.g. v=spf1 include:_spf.mx.cloudflare.net ~all. Verify the current value in your Cloudflare admin console.How many DNS lookups does it use?
Can I have a separate SPF record just for this provider?
v=spf1) record. Publishing two causes a permerror. Merge every sender into a single record.