ZeroHook
ProductSolutionsBlogToolsPricingCompanyContact sales
Run a free scan
  • Product
  • Solutions
  • Blog
  • Tools
  • Pricing
  • Company
  • Contact sales
Sign inRun a free scan
ZeroHook

DNS and email security auditing, without the enterprise contract.

ZeroHook on Product Hunt — Let's stop spoofed email and ship audit proof today.Review ZeroHook on Product Hunt

Explore

  • Product
  • Solutions
  • Blog
  • Tools
  • Pricing

Resources

  • Help center

Company

  • About
  • Contact
  • Contact sales

Legal

  • Privacy
  • Terms
  • Cookies
  • Legal notice

New DNS advisories, monthly

What broke, who it hit, and the record that fixes it.

© 2026 ZeroHook. All rights reserved.

Back to blog
SPF

Google Workspace SPF Record Mistakes

The google workspace spf record is one include. The expensive part is the old hoster line you never deleted.

ZeroHook
ZeroHook Team
Security Analysts
Oct 4, 2026~3 min read
Google Workspace SPF Record Mistakes
Google Admin says your domain is verified. Mailchimp still prints SPF questions in the headers. Wrong layer. Look: the google workspace spf record is one include when Workspace is your only sender. We've had teams nail that line on day one. Six months later DMARC still fails because DNS authorizes Microsoft's old range, or because finance added a second TXT for HubSpot and called it done.

Google Workspace SPF Record (Workspace Only)

If every outbound message leaves through Google Workspace and no SaaS sends as your root domain, publish this TXT on the apex:

v=spf1 include:_spf.google.com -all

What it does

include:_spf.google.com pulls in Google's published SPF chain for Workspace mail. -all tells receivers to fail mail from anywhere else. Google documents the same include in Workspace setup; you're not inventing a custom mechanism.

Where it lives

Your DNS host (Cloudflare, GoDaddy, Route 53, Namecheap). Not inside Google Admin. Admin shows the value to copy. The zone file is yours.

Full syntax rules: zerohook.org/blog/spf-record-syntax-complete-reference. M365 twin post: zerohook.org/blog/microsoft-365-spf-record-template.

Mistakes We See on Workspace Domains

Leftover provider includes

include:spf.protection.outlook.com after you leave Microsoft 365 is the classic. SPF can still "pass" against Google's range for mailbox mail while marketing or ticketing sends from an ESP that isn't in the record.

Two TXT records starting with v=spf1

Finance adds HubSpot in a new TXT instead of editing the existing line. That's PermError. One string per domain.

Softfail by habit

~all lingers from a decade-old tutorial. Production domains in 2026 should end with -all unless you're in a same-day cutover test you plan to close before TTL expires.

Lookup pile-up

Each live include: costs lookups inside Google's chain plus whatever the ESP publishes. Stack four senders on the root without counting and you hit RFC 7208's limit of ten. Gmail won't negotiate. PermError is auth failure.

Warning

A lookup tool that only prints TXT text won't count nested includes. Use a validator that reports lookup depth before you blame DMARC.

Workspace Plus ESP (Copy-Paste Templates)

1

Workspace + Mailchimp on the root domain (check lookup count after publish):

v=spf1 include:_spf.google.com include:servers.mcsv.net -all
2

Workspace + HubSpot marketing:

v=spf1 include:_spf.google.com include:spf.hubspotemail.net -all
3

Workspace + SendGrid transactional:

v=spf1 include:_spf.google.com include:sendgrid.net -all
4

Cloudflare: DNS → Add record → Type TXT → Name @ → paste the single line → Save. Delete any other TXT that starts with v=spf1.

5

Validate at zerohook.org/spf-checker. If you're over ten lookups, drop dead includes or move bulk mail to a subdomain like mail.yourdomain.com with its own SPF.

Frequently Asked Questions

Key takeaways

1

Standard Workspace-only SPF: v=spf1 include:_spf.google.com -all

2

Remove old provider includes the week you migrate; Admin green checks don't edit DNS for you.

3

One SPF TXT per domain; merge ESP includes into that line.

4

Count lookups after every ESP signup; PermError shows up late.

5

Pair SPF with DKIM and DMARC so Workspace mail survives Gmail and Microsoft bulk rules.

Paste your TXT at zerohook.org/spf-checker before you delete Microsoft's include and wonder why half your mail still authenticates against the wrong network.

Share this analysis

Help others discover this content

Fix DNS before the next audit
Provider-specific copy-paste fixes for Cloudflare, Route53, GoDaddy, and more.
Start free scan

More from our blog

SPF Record Syntax: Complete Reference
SPF

SPF Record Syntax: Complete Reference

SPF record syntax from v=spf1 through -all: includes, lookup limits, permerror traps, and provider templates. The reference we use before editing any production TXT record.

Microsoft 365 SPF Record Template
SPF

Microsoft 365 SPF Record Template

Copy-paste SPF templates for Microsoft 365-only mail, M365 plus Mailchimp or HubSpot, and hybrid setups. Cloudflare and GoDaddy publish steps included.

Fix SPF Permerror (Too Many Lookups)
SPF

Fix SPF Permerror (Too Many Lookups)

SPF PermError stops SPF evaluation entirely, breaking deliverability and DMARC alignment. Fix syntax errors, merge duplicate TXT records, and stay under the 10 DNS lookup limit.