SPF Checker

Validate a domain’s SPF record, follow every include and count DNS lookups to make sure your mail servers are authorized and SPF never hits a permanent error.

What is an SPF record?

SPF (Sender Policy Framework, RFC 7208) is an email authentication method that lists the servers allowed to send mail for a domain. The list is published as a single TXT record that starts with v=spf1. When a message arrives, the receiving server compares the sending IP address with that list.

A missing or broken SPF record makes legitimate mail more likely to land in spam, and it weakens DMARC, which relies on SPF or DKIM passing with alignment.

How this SPF checker works

  • We fetch all TXT records of the domain and find the one that starts with v=spf1.
  • Every mechanism and modifier is parsed and validated: ip4 and ip6 ranges, include, a, mx, exists, redirect and the final all.
  • We recursively follow each include and redirect, build the include tree and count every DNS-querying term.
  • You see the total number of DNS lookups out of 10, void lookups, loops and every syntax problem with a recommendation.

SPF record example

A domain that sends through its own server and Google Workspace might publish:

v=spf1 ip4:203.0.113.10 include:_spf.google.com -all

It authorizes one IPv4 address and Google’s mail servers, and asks receivers to fail every other sender. Each include adds at least one DNS lookup, so keep the list of services short.

The 10 DNS lookup limit

To protect receivers from abuse, SPF evaluation may trigger no more than 10 DNS lookups. The mechanisms include, a, mx, ptr and exists and the redirect modifier each cost one lookup, including those inside nested includes. ip4, ip6 and all are free. If the total exceeds 10, the result is a permanent error (permerror) and SPF fails for every message.

Exceeding the limit is the most common SPF problem for growing companies that add a new email service every few months. To stay under it: remove services you no longer use, replace a and mx with explicit ip4/ip6 ranges, and ask vendors for a narrower include.

SPF qualifiers: -all, ~all and ?all

  • -all (fail) — unauthorized senders fail. The strictest and recommended ending once you are sure the list is complete.
  • ~all (softfail) — unauthorized mail is accepted but marked as suspicious. Common during migration and widely used together with DMARC.
  • ?all (neutral) — no statement at all. It provides no protection.
  • +all (pass) — authorizes everyone. Never use it: it lets anybody send mail as your domain.

Common SPF errors

  • Multiple SPF records — a domain must have exactly one v=spf1 record. Merge them into one.
  • Too many DNS lookups — more than 10 lookups causes permerror; flatten or remove includes.
  • Includes of domains without SPF — they count as void lookups; more than 2 cause a permanent error.
  • Use of ptr — deprecated, slow and ignored by many receivers.
  • Terms after all — anything after the all mechanism is never evaluated.

Frequently asked questions

How do I check my SPF record?

Enter your domain in the SPF checker above. The tool finds the v=spf1 TXT record, validates its syntax, follows all includes and shows the total number of DNS lookups along with any errors and recommendations.

What does "too many DNS lookups" mean?

SPF allows at most 10 DNS-querying terms during evaluation, counting nested includes. When the record needs more, receivers return a permanent error and SPF fails. Remove unused services or replace includes and a/mx mechanisms with explicit IP ranges.

Can a domain have two SPF records?

No. Publishing more than one v=spf1 record causes a permanent error. Combine all authorized senders into a single record.

Should I use -all or ~all?

-all is stricter and recommended once every legitimate sender is listed. ~all is safer during changes. With an enforced DMARC policy, the practical difference is small because DMARC decides the final outcome.

Does SPF protect the From address users see?

Not by itself. SPF checks the envelope sender (Return-Path), not the visible From header. DMARC adds alignment between them, which is why you need both.

How do I add a new email service to SPF?

Add the include or IP range provided by the service before the all mechanism, for example include:sendgrid.net. Then run the SPF checker again to make sure you are still within the 10 lookup limit.

Is this SPF checker free?

Yes, it is completely free with no sign-up. We do not store the domains you check.

More free email tools