Questions · Updated 2026-09-28
Can I have two SPF records on one domain?
No. A domain name carries one SPF record, and two SPF records on one name invalidate both. Merge include:_spf.agentisend-dns.com into the record that is already there, then POST /domains/{id}/verify re-checks it and GET /domains/{id} shows what DNS returned.
No. A domain name carries one SPF record, and two SPF records on one name invalidate both, so a receiver that finds two treats the domain as having none. Merge our mechanism into the record that is already published, then call POST /domains/{id}/verify. GET /domains/{id} returns the SPF row with status and observed, which is the record DNS handed back, so you can see whether the merge took.
Merge, do not add
The SPF value we hand out is v=spf1 include:_spf.agentisend-dns.com -all. When the name already has a record, keep that record and add the include to it. Domains and DNS shows the result for a domain that also uses another provider:
v=spf1 include:_spf.agentisend-dns.com include:_spf.mailprovider.example -allThe fix on the SPF row says the same thing in full: "Recommended, not required — the domain verifies and sends without a root SPF once the return-path records resolve. If the root already has an SPF record, do not add a second one — merge ours into it: either the ip4: mechanisms above, or include:_spf.agentisend-dns.com. include:_spf.agentisend.com still authorises us. The include is accepted only when it currently publishes every sending IP; an include that does not resolve does not authorise us."
What verification tells you
Every record on GET /domains/{id} carries status (pending, verified, failed or recommended), observed, reason and fix. The SPF row is advice: its status reads recommended until it resolves, and it never moves the domain's own status. Two warnings can appear in warnings on the same response. spf_conflict says "This domain already publishes an SPF record that does not include us." and its fix is "Replace the existing TXT with the merged record we return. This is advice: the domain can verify and send without the apex SPF once the return-path records resolve." The response carries that merged record under merged. spf_lookup_limit says "Merging our include into the existing SPF record would pass the 10-lookup limit." and its fix is "Do not add a second SPF record. Rely on the return-path SPF, which is required anyway. The apex SPF is advice and never blocks sending."
curl -sS -X POST https://api.agentisend.com/domains/9c8f8f0e-3d1a-4d3f-9a1e-2b7c1a0f5e42/verify \
-H "Authorization: Bearer $AGENTISEND_API_KEY" \
-H "Idempotency-Key: $(uuidgen)"201
{
"click_tracking": true,
"created_at": "2026-09-04T09:14:00Z",
"dkim_selector": "string",
"id": "9c8f8f0e-3d1a-4d3f-9a1e-2b7c1a0f5e42",
"name": "yourdomain.com",
"open_tracking": true,
"provider_hints": {},
"recent_events": []
}The return-path record is a separate name
The required SPF is the TXT on send.<domain> (or bounce.<domain>), next to the return-path MX. That name is ours to define on a new domain, so it usually has no existing record and takes our value as written. GET /domains/{id}/setup lists that row with host relative to your zone and the value to paste. If it does already have one, the same rule applies there: one record, merged.
Where to edit
One page per DNS host, each with that host's own steps for editing an existing TXT record: Cloudflare, Namecheap, GoDaddy, Route 53, Google Domains, Porkbun, Hostinger.