SPF tells receiving servers which machines may send mail for your domain.
WHAT IT IS
A TXT record listing your authorised sending sources. A receiving server checks the sending address against that list.
SETTING IT UP
cPanel > Email Deliverability. Where SPF is missing or wrong, click Repair and cPanel installs the correct record.
If your DNS is at Cloudflare or another provider, use "Install the suggested record" to view the value and add it there instead. The Repair button cannot change records we do not host.
IF YOU SEND FROM ELSEWHERE TOO
Google Workspace, Microsoft 365, SendGrid, Brevo, Mailgun and similar each need including in the same record. You must have exactly one SPF record, containing every source.
Two SPF records is an error that causes the check to fail entirely, and it is a common mistake when adding a second provider.
COMMON PROBLEMS
An old record from a previous host still listed A second record added rather than the existing one extended Too many lookups, which some receivers treat as a failure
If mail from one source authenticates and another does not, the SPF record is the first thing to examine.