📧 SPF Record Checker
Verify SPF (Sender Policy Framework) records for any domain to ensure proper email authentication. SPF records help prevent email spoofing and improve email deliverability by authorizing mail servers to send emails on behalf of your domain.
What the lookup returns
This tool queries live DNS. The domain is sent to SimpleMoney's network-tools API,
which reads the domain's TXT records, keeps the first one beginning
v=spf1, and splits it into mechanisms:
v=spf1 ip4:198.51.100.0/24 include:_spf.google.com include:sendgrid.net ~all
You get back the raw record, the mechanism count, the include: targets,
any redirect=, and whether an all mechanism is present.
Publish SPF at the domain itself, not at a _spf label.
The ten-lookup limit, and why includes blow it
A receiver is allowed to spend ten DNS lookups evaluating your record.
include, a, mx, ptr,
exists and redirect each cost one. ip4,
ip6 and all cost nothing. The count is recursive, which is
the trap: include:_spf.google.com looks like one, but that record
contains three further includes, so it spends four of your ten. Chain three vendors
like that and you are over the limit with a record that still looks short.
Past ten, evaluation stops with permerror, which receivers treat as
a non-pass. This checker lists the include targets but does not follow them, so count
the nested ones yourself; swapping an include for ip4 ranges is the
usual fix.
-all (hard fail) tells
receivers to treat unlisted senders as unauthorised; ~all (soft fail)
only asks them to accept and mark it. Under DMARC both count as an SPF fail, but
without DMARC, ~all usually still lands in the inbox. +all
authorises the entire internet and should never be published.Frequently asked questions
What is the difference between -all and ~all?
Hard fail versus soft fail. With -all a receiver is told the message is
unauthorised and may reject it outright; with ~all it is told to accept
but treat it as suspect. Use ~all while you are still finding your
senders, then tighten.
How many DNS lookups does my SPF record use?
Add one for every include, a, mx, ptr, exists and redirect, then the same again for every record those pull in. Ten is the ceiling for the whole tree.
Can I have two SPF records?
No. Two v=spf1 TXT records on one domain is a permerror. Merge them
into a single record by combining the mechanisms - which is also when the lookup
count needs rechecking.