📧 SPF Record Checker

Verify SPF (Sender Policy Framework) records for any domain to ensure proper email authentication. SPF records help prevent email spoofing and improve email deliverability by authorizing mail servers to send emails on behalf of your domain.

💡 Tip: Enter your domain name and click "Check SPF Record" to retrieve and validate the SPF record configuration.
Enter a domain name and click "Check SPF Record" to view results.

What the lookup returns

This tool queries live DNS. The domain is sent to SimpleMoney's network-tools API, which reads the domain's TXT records, keeps the first one beginning v=spf1, and splits it into mechanisms:

v=spf1 ip4:198.51.100.0/24 include:_spf.google.com include:sendgrid.net ~all

You get back the raw record, the mechanism count, the include: targets, any redirect=, and whether an all mechanism is present. Publish SPF at the domain itself, not at a _spf label.

The ten-lookup limit, and why includes blow it

A receiver is allowed to spend ten DNS lookups evaluating your record. include, a, mx, ptr, exists and redirect each cost one. ip4, ip6 and all cost nothing. The count is recursive, which is the trap: include:_spf.google.com looks like one, but that record contains three further includes, so it spends four of your ten. Chain three vendors like that and you are over the limit with a record that still looks short.

Past ten, evaluation stops with permerror, which receivers treat as a non-pass. This checker lists the include targets but does not follow them, so count the nested ones yourself; swapping an include for ip4 ranges is the usual fix.

The final mechanism matters. -all (hard fail) tells receivers to treat unlisted senders as unauthorised; ~all (soft fail) only asks them to accept and mark it. Under DMARC both count as an SPF fail, but without DMARC, ~all usually still lands in the inbox. +all authorises the entire internet and should never be published.

Frequently asked questions

What is the difference between -all and ~all?

Hard fail versus soft fail. With -all a receiver is told the message is unauthorised and may reject it outright; with ~all it is told to accept but treat it as suspect. Use ~all while you are still finding your senders, then tighten.

How many DNS lookups does my SPF record use?

Add one for every include, a, mx, ptr, exists and redirect, then the same again for every record those pull in. Ten is the ceiling for the whole tree.

Can I have two SPF records?

No. Two v=spf1 TXT records on one domain is a permerror. Merge them into a single record by combining the mechanisms - which is also when the lookup count needs rechecking.