Business
Business Security · Overview Executive Protection
Individual
Personal Protection · Overview Personal Credential Scan
Programs
Family Offices Wealth Firms Sports & Entertainment Agencies Reputation Threat Intelligence Wealth Manager Program Business Broker Program Partners
Intelligence
Research Library Threat Intelligence Global Breach Map Recent Breach Disclosures
Company
How It Works About Contact
Sign In
Cyber-intelligence glossary

SPF

Sender Policy Framework

A DNS record listing which mail servers are authorized to send email on behalf of a domain.

Definition

SPF (Sender Policy Framework) is a DNS TXT record that lists the IP addresses and hostnames authorized to send mail on behalf of a domain. Receiving mail servers check inbound mail against the SPF record and can reject or quarantine mail from unauthorized sources. SPF is standardized in RFC 7208. SPF alone is insufficient for full email authentication — it does not survive mail forwarding intact and does not authenticate the visible From: header. SPF combined with DKIM and enforced by DMARC is the standard pattern. An SPF record that ends in ~all (soft-fail) or ?all (neutral) provides weaker protection than -all (hard-fail).

Why it matters

A missing or permissive SPF record on an advisor tenant domain lets attackers spoof mail from that domain to the principal, family office, or counterparty. LeakTrace audits SPF configuration across every advisor tenant during the baseline scan and monitors for drift or misconfiguration over time.

Related LeakTrace pages
Related terms
Discovery call
Mutual NDA on request. Reply within one business day.
Book at [email protected]. Full glossary at getleaktrace.com/glossary. Frequently asked questions at getleaktrace.com/faq.