Skip to content

Free tool

SPF record checker

Enter a domain to read its SPF record, follow every include and count DNS lookups against the limit of 10. You get a verdict and the exact fix for each issue.

Public DNS lookups only. Nothing is sent to the domain.

Quick answer

A healthy SPF record is one TXT record starting with v=spf1, lists every service that sends for you, needs 10 DNS lookups or fewer, and ends with ~all or -all. Two records, +all, or more than 10 lookups make receivers treat SPF as broken.

What this tool checks

Exactly one SPF record. Two v=spf1 records on the same domain are a permanent error. Receivers stop evaluating SPF entirely.

DNS lookup count. include, a, mx, ptr, exists and redirect each cost a lookup, including those inside included records. We follow them recursively, stop at the limit and detect include loops.

The all mechanism. We read how the record ends: -all and ~all protect you, ?all is neutral, +all lets anyone send as you, and no all at all defaults to neutral.

Broken includes and deprecated terms. Includes pointing at domains without an SPF record, unknown mechanisms and the deprecated ptr mechanism are all flagged.

What each ending means

SPF all qualifiers and how receivers treat unlisted servers
EndingResult for unlisted serversUse it when
-allFailYou know every service that sends for you
~allSoft failDefault choice, alongside DMARC
?allNeutralRarely useful: says nothing
+allPassNever: anyone can send as your domain

How to fix common issues

Too many DNS lookups

Remove includes for services you no longer use first. Then replace a and mx with the ip4 or ip6 ranges they resolve to, or move one sender to a subdomain with its own SPF record. Avoid flattening tools that hardcode provider IPs unless they keep them updated.

Multiple SPF records

Merge them: keep one v=spf1, put every include and ip4/ip6 from both records in it, and end with a single all. Delete the other TXT record.

+all or ?all

Change the ending to ~all. Once DMARC reports show all your legitimate mail passing, you can move to -all.

Your email provider is missing

Add the include your provider documents, for example include:amazonses.com for Amazon SES. With a custom MAIL FROM domain, SPF is checked on that subdomain, which is how Lumail sets it up for you.

Frequently asked questions

What is the SPF 10 DNS lookup limit?

RFC 7208 caps SPF evaluation at 10 DNS-querying terms: include, a, mx, ptr, exists and redirect, counted across every nested include. Past 10, receivers return a permanent error and SPF fails for all your mail.

Should I use ~all or -all?

Both are fine with DMARC in place, since DMARC decides what happens to failing mail. ~all is the safer default while you are still discovering senders. -all is stricter once you are sure the record is complete.

Can a domain have two SPF records?

No. With more than one v=spf1 TXT record, receivers return a permanent error and treat SPF as failed. Merge everything into one record.

Does SPF alone stop spoofing?

No. SPF checks the hidden envelope sender, not the From address people see. You need DKIM and a DMARC policy to protect the visible From domain.

Does this tool contact my mail server?

No. It only reads public TXT records from DNS, with a timeout on each query. Nothing is sent to the domain.

Related tools and guides

Authenticated sending, set up for you.

3,000 emails a month free. Unlimited subscribers on every plan. Campaigns, automations and transactional email on one domain.