Skip to content
arrow_back
search
ISM-0574 policy ASD Information Security Manual (ISM)

Use SPF to Authorise Email Servers

SPF helps confirm which email servers are allowed to send emails for your organisation's domain.

record_voice_over

Plain language

The Sender Policy Framework (SPF) is a safety measure to make sure only approved email servers can send emails on behalf of your organisation. This helps prevent scammers from sending fake emails using your business name, which could damage your reputation and lead to people losing trust in your organisation.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

May 2023

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

SPF is used to specify authorised email servers (or lack thereof) for an organisation's domains (including subdomains).
policy ASD Information Security Manual (ISM) ISM-0574
priority_high

Why it matters

Without SPF DNS records, attackers can spoof your domain in email, enabling phishing, fraud and reputational harm.

settings

Operational notes

Maintain SPF DNS TXT records for all domains/subdomains; update senders when mail services change and validate syntax/lookup limits.

Mapping detail

Mapping

Direction

Controls