Validate a domain’s SPF record, follow every include and count DNS lookups to make sure your mail servers are authorized and SPF never hits a permanent error.
SPF (Sender Policy Framework, RFC 7208) is an email authentication method that lists the servers allowed to send mail for a domain. The list is published as a single TXT record that starts with v=spf1. When a message arrives, the receiving server compares the sending IP address with that list.
A missing or broken SPF record makes legitimate mail more likely to land in spam, and it weakens DMARC, which relies on SPF or DKIM passing with alignment.
A domain that sends through its own server and Google Workspace might publish:
v=spf1 ip4:203.0.113.10 include:_spf.google.com -all
It authorizes one IPv4 address and Google’s mail servers, and asks receivers to fail every other sender. Each include adds at least one DNS lookup, so keep the list of services short.
To protect receivers from abuse, SPF evaluation may trigger no more than 10 DNS lookups. The mechanisms include, a, mx, ptr and exists and the redirect modifier each cost one lookup, including those inside nested includes. ip4, ip6 and all are free. If the total exceeds 10, the result is a permanent error (permerror) and SPF fails for every message.
Exceeding the limit is the most common SPF problem for growing companies that add a new email service every few months. To stay under it: remove services you no longer use, replace a and mx with explicit ip4/ip6 ranges, and ask vendors for a narrower include.
Enter your domain in the SPF checker above. The tool finds the v=spf1 TXT record, validates its syntax, follows all includes and shows the total number of DNS lookups along with any errors and recommendations.
SPF allows at most 10 DNS-querying terms during evaluation, counting nested includes. When the record needs more, receivers return a permanent error and SPF fails. Remove unused services or replace includes and a/mx mechanisms with explicit IP ranges.
No. Publishing more than one v=spf1 record causes a permanent error. Combine all authorized senders into a single record.
-all is stricter and recommended once every legitimate sender is listed. ~all is safer during changes. With an enforced DMARC policy, the practical difference is small because DMARC decides the final outcome.
Not by itself. SPF checks the envelope sender (Return-Path), not the visible From header. DMARC adds alignment between them, which is why you need both.
Add the include or IP range provided by the service before the all mechanism, for example include:sendgrid.net. Then run the SPF checker again to make sure you are still within the 10 lookup limit.
Yes, it is completely free with no sign-up. We do not store the domains you check.