Definition · DNS & Email Spoofing
What is TXT Record?
A TXT record attaches arbitrary text to a DNS name. DNS itself places no meaning on the contents, so over time the record type became the general-purpose place to publish machine-readable policy. Most of the email authentication stack lives in TXT records, as do the verification strings that SaaS providers use to confirm you control a domain.
What TXT records are used for
example.com. TXT "v=spf1 include:_spf.google.com -all"
_dmarc.example.com. TXT "v=DMARC1; p=reject; rua=mailto:dmarc@example.com"
sel1._domainkey.example.com. TXT "v=DKIM1; k=rsa; p=MIGfMA0GCSq..."
example.com. TXT "some-vendor-domain-verification=8f3a..."
- SPF — which hosts may send mail for the domain
- DKIM — the public keys used to verify message signatures
- DMARC — what receivers should do when alignment fails, and where to send reports
- MTA-STS and TLS-RPT — policy discovery and reporting for mail transport encryption
- BIMI — the logo reference for participating mailbox providers
- Domain ownership proofs for cloud, analytics and certificate providers
Practical constraints
A single TXT string is limited to 255 characters, so longer values — typically RSA DKIM keys — are published as several concatenated strings inside one record. Large record sets also push responses past the classic 512-byte UDP limit, requiring EDNS(0) or a TCP retry; badly configured firewalls that block DNS over TCP cause intermittent failures that are hard to attribute.
Only one SPF record may exist per name. A second one is a configuration error rather than an addition, and receivers are expected to treat the result as permanently failing. SPF also caps how many DNS lookups evaluation may trigger, which is covered under the SPF lookup limit.
Information disclosure
TXT records are public, and they are an unusually candid inventory. Accumulated verification tokens name the vendors an organisation uses — helpdesk, CRM, cloud tenant, code hosting — which is useful to anyone doing OSINT before a phishing or BEC attempt. Removing tokens for services you no longer use is a small piece of attack surface reduction, and it prevents an old token from being treated as a live claim.
Related concepts
See DNS record types, DNS and email spoofing, and DNSSEC for signing the answers so a resolver can tell they were not altered in transit.