SPF record checker.
Look up a domain's SPF record and see which servers it allows to send mail. The check counts visible mechanisms against SPF's limit of 10 DNS lookups and does not recursively resolve includes.
What this check can tell you
The result shows the published SPF record, its all qualifier, and a count of the lookup mechanisms in that record. It flags a missing record, more than one record, +all, ?all, a missing all, a count near or over 10, and the deprecated ptr mechanism. It reads the record at the exact name you enter, so check the domain your mail's return-path uses. SPF passes DMARC only when that domain aligns with your From domain, which the DMARC checker covers.
Limit: Nested include records are not expanded here, so this check cannot certify the effective recursive lookup total. It also cannot show whether a real email passed SPF.
How to read the SPF result
Each finding is graded pass, warning, or fail, and failing findings come with the fix.
- No SPF record
- Fail. Receivers cannot check which servers may send for the domain. Publish a TXT record that starts with
v=spf1. - More than one SPF record
- Fail. A domain may publish one. Two or more are a permanent error, and receivers can ignore SPF. Merge them into a single record.
- The all qualifier
-alland~allpass.?alland a missing all warn, because receivers make no judgement on unlisted servers.+allfails: it authorizes every server on the internet.- DNS-lookup mechanisms
- The count of include, a, mx, ptr, exists, and redirect in this record. Seven or fewer passes, 8 to 10 warns, and more than 10 fails. The ip4, ip6, and all mechanisms are free.
- The ptr mechanism
- Warning. It is deprecated, slow, and unreliable. Replace it with explicit a, mx, ip4, or ip6 mechanisms.
Why the lookup count is a floor
SPF allows 10 DNS lookups per check (RFC 7208). Each include, a, mx, ptr, exists, and redirect costs one, and every lookup inside an included record is added to your total. This checker counts the mechanisms in the record you published and does not follow includes, so the real total can be higher than the number shown.
To find the true total, open the TXT record behind each include and count its lookup mechanisms. When you are over, drop senders you no longer use, or replace an include with ip4 and ip6 ranges you control. Flattening a provider's include into IP addresses stops working the day the provider changes its ranges.
An annotated SPF record
A domain that sends from one of its own servers and one mail provider. It costs one DNS lookup.
example.com. TXT "v=spf1 ip4:203.0.113.10 include:_spf.mailer.example ~all"What each part does
v=spf1- The version token. A TXT record is an SPF record only if it starts with this.
ip4:203.0.113.10- Authorizes one IPv4 address and costs no lookup.
ip6:does the same for IPv6. include:_spf.mailer.example- Authorizes the servers in that provider's SPF record. It costs one lookup, plus every lookup inside the provider's record.
~all- Ends the record. Mail from any other server softfails.
Common SPF problems and fixes
- Two SPF records
- A second team or vendor tool published its own. Combine every include and IP range into one record and delete the other.
- More than 10 lookups
- Remove includes for services you no longer send from. Swap an include that rarely changes for ip4 and ip6 ranges. Send each provider's mail from its own subdomain so each record has its own budget of 10.
- Mail from a subdomain fails
- SPF does not inherit. Publish a record on the subdomain that sends, then check that name here.
- SPF passes but DMARC fails
- DMARC needs the return-path domain that passed SPF to align with the visible From domain. Use a return-path on your own domain, or rely on an aligned DKIM signature and inspect it with the DKIM checker.
- Forwarded mail fails SPF
- Expected. A forwarding server is not in your record. DKIM signatures survive forwarding, so keep DKIM aligned and enforce DMARC on that.
- +all, ?all, or no all
- End the record with
~allwhile you confirm your senders, then consider-all.