Skip to content

TechDirectArchive

Hands-on IT, Cloud, Security, Veeam & DevOps

  • Home
  • About
  • Advertise With US
  • Reviews
  • Contact
  • Toggle search form

How to setup SPF and TXT Records in AWS

Posted on 13/12/201817/08/2026 Dickson Victor By Dickson Victor No Comments on How to setup SPF and TXT Records in AWS
  1. Home
  2. AWS/Azure/OpenShift
  3. How to setup SPF and TXT Records in AWS
SPF records

An SPF record is a TXT record that is part of a domain’s DNS zone file. The TXT record specifies a list of authorized hostnames/IP addresses that mail can originate from for a given domain name. Kindly refer to the following similar guides: How to add a custom domain name to Azure Active Directory, and How to deploy WordPress on Azure App Service, and “how to add and verify a custom domain name to Azure Active Directory“.

Once this entry is placed within the DNS zone, no further configuration is necessary to take advantage of servers that incorporate SPF checking into their anti-spam systems. This SPF record is added the same way as a regular A, MX, or CNAME record.

When a server sends an e-mail from a domain techdirectarchive.de or techdirectarchive.com, the Internet Protocol (IP) needs an SPF record to get identified as a trusted sender.

Also, see Domain Name System Protocol: Client Registration Issue, how to fix “DNS Bad key 9017: The Cluster Name registration failed of one or more associated DNS names“, and Domain Name System: How to create a DNS record.

How to setup SPF and TXT Records in AWS

Sender Policy Framework (SPF) is a method of fighting spam. When a server sends an e-mail from a domain techdirectarchive.de or techdirectarchive.com, the Internet Protocol (IP) needs an SPF record to get identified as a trusted sender.

Step-by-step guide for adding an SPF record
– Sign in to the AWS Management Console.
– Navigate to Route 53 dashboard at https://console.aws.amazon.com/route53/
– In the left navigation panel, under Dashboard,

– Click Hosted Zones. e.g. techdirectarchive.com
– Click on the domain name hosted zone that you want to update.
– On the DNS hosted zone page,
– create a new SPF record by completing the following actions
– Click Create Record Set button from the dashboard top menu.
– Leave the Name field empty.

From the Type dropdown list
– Select SPF – Sender Policy Framework.
In the Time To Leave (TTL) in seconds field,
– Enter a value of 3600 (1 hour) for Time to Live. In the Value text box,
– Enter the SPF value required, e.g. “v=spf1 include:_spf.google.com-all”.

v=spf1 include:_spf.google.com-all

Note: If you do not use Google mail servers, replace include:_spf.google.com with the authorized mail server hostname/IP address e.g. “v=spf1 ip4:IPAddress/32-all”. From the Routing Policy dropdown list.

  • Select Simple as the routing method for the SPF DNS record.
  • Click Create to add the new SPF record to the DNS-hosted zone.

If you have multiple DNS hosted zone without SPF record sets (see the Audit section to determine which domains require SPF records).

Note: Adding an SPF record also requires a TXT record.

Step for adding a TXT record

Step for adding a TXT record
– Sign in to the AWS Management Console.
– Navigate to Route 53 dashboard at https://console.aws.amazon.com/route53/
– In the left navigation panel,
– Under Dashboard,
– Click Hosted Zones.
– Click on the hosted zone that you want to update (e. g. techdirectarchive.com).
– On the DNS hosted zone page,
– Create a new TXT record by completing the following actions
– Click Create Record Set button from the dashboard top menu.
– Leave the Name field empty.
– From the Type dropdown list
– Select TXT – text.

In the TTL (Seconds) field, Enter a value of 3600 (1 hour) for Time to Live.

In the Value text box, enter the TXT value required, e.g. “v=spf1 mx ip4:IPAddress/32 a:spf.protecxxx.outlook.com a:spf.crsend.com -all”.

v=spf1 mx ip4:IPAddress/32 a:spf.protecxxx.outlook.com a:spf.crsend.com -all

From the Routing Policy dropdown list, select Simple as the routing method for the TXT DNS record. Click Create to add the new TXT record to the DNS-hosted zone.

I hope you found this blog post on how to setup SPF and TXT Records in AWS helpful? Please let me know in the comment session if you have any questions.

Thank you for reading this post. Kindly share it with others.

  • Share on X (Opens in new window) X
  • Share on Reddit (Opens in new window) Reddit
  • Share on LinkedIn (Opens in new window) LinkedIn
  • Share on Facebook (Opens in new window) Facebook
  • Share on Pinterest (Opens in new window) Pinterest
  • Share on Tumblr (Opens in new window) Tumblr
  • Share on Telegram (Opens in new window) Telegram
  • Share on WhatsApp (Opens in new window) WhatsApp
  • Share on Mastodon (Opens in new window) Mastodon
  • Share on Bluesky (Opens in new window) Bluesky
AWS/Azure/OpenShift Tags:AWS, DNS, DNSRecord, FQDN

Post navigation

Previous Post: How to disconnect a Remote Desktop User
Next Post: Get Started with OpsWorks for Chef Automate

Related Posts

  • ALB Banner e1783275763693
    Azure Load Balancer: Configuring for SQL Server Always On Availability Group Listener on Azure Virtual Machines AWS/Azure/OpenShift
  • Webp.net resizeimage 1
    Automate Infrastructure Deployments in the Cloud with Ansible and Azure Pipelines AWS/Azure/OpenShift
  • image 54
    How to enable Amazon S3 default bucket encryption using S3 Console AWS/Azure/OpenShift
  • image 81
    How to Deploy Dynamic Website to AWS EC2 AWS/Azure/OpenShift
  • Azure App Service
    How to Restore Deleted Azure App Service Using PowerShell Automation
  • BLOG LOGO
    How to create a static pod in Kubernetes AWS/Azure/OpenShift

More Related Articles

ALB Banner e1783275763693 Azure Load Balancer: Configuring for SQL Server Always On Availability Group Listener on Azure Virtual Machines AWS/Azure/OpenShift
Webp.net resizeimage 1 Automate Infrastructure Deployments in the Cloud with Ansible and Azure Pipelines AWS/Azure/OpenShift
image 54 How to enable Amazon S3 default bucket encryption using S3 Console AWS/Azure/OpenShift
image 81 How to Deploy Dynamic Website to AWS EC2 AWS/Azure/OpenShift
Azure App Service How to Restore Deleted Azure App Service Using PowerShell Automation
BLOG LOGO How to create a static pod in Kubernetes AWS/Azure/OpenShift

Leave a Reply Cancel reply

You must be logged in to post a comment.

Microsoft MVP

vexpert-badge-stars-5

Virtual Background

VEEAMLEGEND

Categories

veeaam100

Veeam Vanguard

  • sonarlite
    How to Setup SonarLint in VS Code for Your App Project Configuration Management Tool
  • computefeature
    How to use Azure Compute Gallery AWS/Azure/OpenShift
  • maxresdefault 2 3
    How to configure WatchGuard WebCenter Network | Monitoring
  • vro and agent deployment
    Deploy Veeam Recovery Orchestrator and Agents to VBR and VEM Backup
  • drivelock 1280x720 1
    The server could not be reached or validated: Timeout expired. The Time out expired prior to obtaining a connection from the pool Security | Vulnerability Scans and Assessment
  • gnome
    Determine the version of GNOME running on your Ubuntu Linux Network | Monitoring
  • physical
    Linux Machine: Is it Virtual or a Physical server Linux
  • Create Password Policies via GPO
    How to Create a Password Policy with Group Policy Object Windows

Subscribe to Blog via Email

Enter your email address to subscribe to this blog and receive notifications of new posts by email.

Join 1,757 other subscribers
  • RSS - Posts
  • RSS - Comments
  • About
  • Authors
  • Write for us
  • Contact
  • Advertise with us
  • General Terms and Conditions
  • Privacy policy
  • Feedly
  • Telegram
  • Youtube
  • Facebook
  • Instagram
  • LinkedIn
  • Tumblr
  • Pinterest
  • Twitter
  • mastodon
  • Bsky

Tags

Active Directory Azure Bitlocker Microsoft Windows PowerShell WDS Windows 10 Windows 11 Windows Deployment Services Windows Server 2016

Copyright © 2026 TechDirectArchive

Loading Comments...

You must be logged in to post a comment.