Google Workspace SPF Record Mistakes
The google workspace spf record is one include. The expensive part is the old hoster line you never deleted.

Google Workspace SPF Record (Workspace Only)
If every outbound message leaves through Google Workspace and no SaaS sends as your root domain, publish this TXT on the apex:
v=spf1 include:_spf.google.com -allWhat it does
include:_spf.google.com pulls in Google's published SPF chain for Workspace mail. -all tells receivers to fail mail from anywhere else. Google documents the same include in Workspace setup; you're not inventing a custom mechanism.
Where it lives
Your DNS host (Cloudflare, GoDaddy, Route 53, Namecheap). Not inside Google Admin. Admin shows the value to copy. The zone file is yours.
Full syntax rules: zerohook.org/blog/spf-record-syntax-complete-reference. M365 twin post: zerohook.org/blog/microsoft-365-spf-record-template.
Mistakes We See on Workspace Domains
Leftover provider includes
include:spf.protection.outlook.com after you leave Microsoft 365 is the classic. SPF can still "pass" against Google's range for mailbox mail while marketing or ticketing sends from an ESP that isn't in the record.
Two TXT records starting with v=spf1
Finance adds HubSpot in a new TXT instead of editing the existing line. That's PermError. One string per domain.
Softfail by habit
~all lingers from a decade-old tutorial. Production domains in 2026 should end with -all unless you're in a same-day cutover test you plan to close before TTL expires.
Lookup pile-up
Each live include: costs lookups inside Google's chain plus whatever the ESP publishes. Stack four senders on the root without counting and you hit RFC 7208's limit of ten. Gmail won't negotiate. PermError is auth failure.
Warning
Workspace Plus ESP (Copy-Paste Templates)
Workspace + Mailchimp on the root domain (check lookup count after publish):
v=spf1 include:_spf.google.com include:servers.mcsv.net -allWorkspace + HubSpot marketing:
v=spf1 include:_spf.google.com include:spf.hubspotemail.net -allWorkspace + SendGrid transactional:
v=spf1 include:_spf.google.com include:sendgrid.net -allCloudflare: DNS → Add record → Type TXT → Name @ → paste the single line → Save. Delete any other TXT that starts with v=spf1.
Validate at zerohook.org/spf-checker. If you're over ten lookups, drop dead includes or move bulk mail to a subdomain like mail.yourdomain.com with its own SPF.
Frequently Asked Questions
Key takeaways
Standard Workspace-only SPF: v=spf1 include:_spf.google.com -all
Remove old provider includes the week you migrate; Admin green checks don't edit DNS for you.
One SPF TXT per domain; merge ESP includes into that line.
Count lookups after every ESP signup; PermError shows up late.
Pair SPF with DKIM and DMARC so Workspace mail survives Gmail and Microsoft bulk rules.
Share this analysis
Help others discover this content
More from our blog

SPF Record Syntax: Complete Reference
SPF record syntax from v=spf1 through -all: includes, lookup limits, permerror traps, and provider templates. The reference we use before editing any production TXT record.

Microsoft 365 SPF Record Template
Copy-paste SPF templates for Microsoft 365-only mail, M365 plus Mailchimp or HubSpot, and hybrid setups. Cloudflare and GoDaddy publish steps included.

Fix SPF Permerror (Too Many Lookups)
SPF PermError stops SPF evaluation entirely, breaking deliverability and DMARC alignment. Fix syntax errors, merge duplicate TXT records, and stay under the 10 DNS lookup limit.