SPF presence

SPF presence is derived from public TXT evidence and indicates whether an SPF policy record is visible for a domain.

Derived postureMail authenticationPresence evidence

What .auDO observes

Visible SPF policy presence

.auDO derives a presence signal from relevant public TXT evidence. The current public signal does not evaluate the complete policy, lookup behaviour, alignment or sender inventory.

Technical fields

spf_presentdns_raw.spf_presenttxt_records

Why it is observed

SPF presence adds bounded mail-posture context

Why it matters

Visible SPF presence can support interpretation of mail-provider movement and mail-authentication posture when read with MX and DMARC evidence.

What visible change may mean

A change may reflect provider migration, sender-inventory updates, third-party sending services, policy tuning or accidental removal.

Interpretation limits

Presence is not policy quality

SPF presence does not establish that every legitimate sender is covered, that the policy evaluates successfully or that impersonation protections are complete.

Common retained observations

SPF presence change

SPF presence change

Where to use this evidence

Read SPF within broader mail-authentication context

The current State surface groups mail-authentication posture around DMARC. Use it as broader context rather than as a dedicated SPF-quality view.

Related signals