Skip to main content
HostingSeller
Shop plans

Reseller playbook · Intermediate · 15 minutes

How to create an SPF record — SPF Across a Client Estate, Without Naming Your Supplier

You are publishing SPF on domains you do not own, for clients who will ring you the day their invoices start bouncing.

Straight answer first

For a reseller, SPF is a handover task with a commercial edge: every client domain needs its own record, and the hostname you put after include: is the one line in public DNS that can tell that client exactly who you buy your hosting from.

Fifteen minutes covers one domain. The work worth doing properly is settling the house wording once, pushing it into the DNS template on your WHM package, and adding the sender inventory to your onboarding form so the client supplies it instead of you guessing.

Written by the Hosting Seller staff · Checked 24 August 2026

Intermediate

Skill assumed

15 minutes

Per client domain

5

Stages at handover

24/7

Cover for you and them

This is written for whoever holds the WHM login, not for the person who owns the mailbox. It assumes a reseller account, a client list and a support address that hears about it when a record is wrong.

Read the leak section before the steps. An SPF record is public, permanent until you change it, and quoted back at you during migration audits, so the wording deserves one careful decision rather than forty hurried ones.

What SPF costs you per client account

Budget ten minutes at handover and about five a year after that. The slow part is never the TXT record; it is the sender inventory — the newsletter tool the client's marketing agency set up, the invoicing platform their bookkeeper uses, the CRM nobody thought to mention. Ask for that list on the onboarding form and the job stays a ten-minute job.

Skip it and you find the missing sender through a ticket six weeks later, which costs you the diagnosis, the fix and the apology. Measured against a monthly hosting fee, one of those tickets can swallow the margin on that account for the quarter.

The include that quietly names your upstream

Anything after include: is visible to anyone who runs a lookup on your client's domain, and it stays visible for as long as the record does. Publish your own mail hostname — the one answering under your private nameservers — rather than a generic supplier hostname, and the record reads as your infrastructure, because as far as the client is concerned it is.

The same discipline applies to a: and mx: mechanisms. If either resolves to a name that is not yours, you have handed a curious client, a rival agency or a prospective acquirer a free look at your cost base, and you have done it in a record they can read without asking permission.

Templating it before you reach forty accounts

One record by hand is fine. Forty is a morning you will not get back, and the fortieth will contain a typo. Put the house record into the DNS template attached to your WHM package so every account built from that package publishes it on the day it is created, then handle only the additions each client genuinely needs.

Keep the template lean: your own sending host and ~all, nothing more. Client-specific includes stack on top per account, which leaves the ten-lookup allowance available for the services that client actually uses rather than spent on inherited entries nobody can account for.

What the reseller platform already carries

On a reseller account here, AutoSSL, daily backups across every client account and Imunify360 run without being scheduled, and overselling is switched on from the start so you are not rationing disk while the client list is still being built. Softaculous sits inside every cPanel you create, which keeps client-side application setup off your desk too.

Support answers for you and for your clients at any hour, which matters when the person chasing a bounced invoice is not the person who pays your bill. The reseller programme carries a seven-day money-back window rather than the thirty days on hosting plans, so put it against a real client domain early.

A business mail inbox open on a laptop

The reseller stack this is written against

Every walkthrough here is tested on the reseller platform we actually sell: WHM over cPanel, private nameservers, NVMe disks, LiteSpeed in front and Softaculous in every account you create.

Setup costs nothing and overselling is enabled from day one, so the client list can grow before the disk allocation has to.

  • Written for the account administrator
  • The supplier-leak risk named up front
  • The step that must be templated, flagged
  • Support that answers your clients as well

Why Hosting Seller

On every plan, as standard

Written for the WHM, not the mailbox

Aimed at whoever administers the account, with the client's view called out separately wherever it differs.

Costed per account

Names the minutes each client costs you at handover and each year afterwards, so the task can be quoted honestly.

The supplier stays yours

Flags every field in this job capable of revealing who you buy hosting from before a client ever reads it.

Scales past a handful

Says which part has to move into a package default before your account list runs into the dozens.

One record, five stages

Five stages of steady work, with the sender inventory named as the only genuinely slow one.

Cover for the awkward hour

Support answers for you and for your clients at any hour, which is when deliverability questions tend to land.

First Steps

From choosing to live

  1. 1

    Collect the sender list from the client, not from memory

    Put it on the onboarding form: hosting mail, newsletter platform, CRM, invoicing tool, anything that sends as them. A record built from assumptions is a record you will be editing again next month.

  2. 2

    Write one record, and keep it to one

    v=spf1, your own sending host, an include: per genuine third party, then ~all. A second SPF record does not extend the first; it invalidates both, and the client's mail degrades while each record looks perfectly correct on its own.

  3. 3

    Publish it in the zone you actually control

    Edit it in WHM or in the client's own cPanel, depending on your handover model. Where the client's agency answers DNS elsewhere, the record has to go there instead — the zone you can see is not always the zone the world reads.

  4. 4

    Spend the ten lookups deliberately

    SPF allows ten DNS lookups, and three nested includes from mainstream marketing platforms will use most of them. Prune the services the client has stopped paying for before you start flattening anything by hand.

  5. 5

    Validate it, then write it into the client file

    A checking tool confirms the syntax and counts the lookups. Record which services the record covers, so whoever picks up the account next is not reverse-engineering your reasoning at eleven at night.

In the Box

Packed with every plan

  • WHM for you, and a cPanel of their own for every client
  • Private nameservers running under your own brand
  • Overselling switched on from the start
  • You set the limits each client account gets
  • Daily backups across every client account
  • Imunify360 standing guard on every client site
  • Free SSL on every site you host for somebody else
  • Softaculous inside every account you create
  • Ready to wire straight into WHMCS billing
  • Seven days money-back on reseller, thirty on hosting plans

Across the Counter

Things people ask us all the time

A client's newsletter platform fails SPF even though I added their include — whose problem is that?

Theirs to fix, yours to diagnose. The platform is almost certainly sending from its own envelope domain, so SPF passes on that domain and alignment fails on the client's. Point them at the platform's custom-domain or DKIM setup, and bill the diagnosis rather than absorbing it.

Can one SPF record cover every domain on my reseller account?

No — SPF is published per domain, so every client domain carries its own. What you can share is the wording: put the house record into the DNS template on your WHM package and each new account starts life with it already in the zone.

Can a client work out which company actually runs the server?

Only if you let them. Private nameservers, your own mail hostname in the SPF record and packages named by you keep the account looking like yours. The fields worth auditing are the DNS zone, the hostnames on the certificate, and anything that turns up in a message header.

What happens to a client account if that client leaves me?

It moves as a standard cPanel backup, because the panel is cPanel and the whole trade already runs it. That portability cuts both ways, and saying so openly is good business — clients who know they are not locked in argue about renewals far less.

Read next

  • Website Builder

    A quick build for the client who wants a site next week rather than a discovery workshop.

  • Domain Names

    Register and transfer client names in one place — year one free with annual hosting.

Moving your site to another host? Start with this checklist.

A step-by-step order of work for a move your visitors never spot: which files to copy first, how to carry email across without losing one message, the right moment to repoint DNS, and the two mistakes behind nearly every hour of downtime people ring us about.

One email brings the checklist, then now and again a note about running a site properly. Leave the list whenever you feel like it. Our privacy policy spells out the rest.

Put your own name on the hosting.

WHM, private nameservers and a cPanel of their own for every client — with support that answers them as well as you.

See Domain Names plans