SPF Record Checker

Check that a domain's SPF record is valid, stays under the 10-lookup limit and ends the right way. DKIM and DMARC are checked at the same time.

  • Free
  • No Sign-Up
  • Live Lookup

Examples:

How to Use

How to use the SPF Checker

  1. 01

    Enter a domain

    The part after the @ in your email address. Pasting a whole address works.

  2. 02

    Check

    The SPF record is read and every include is followed to count DNS lookups.

  3. 03

    Fix what is red

    Each note says what is wrong and what to change.

Email Authentication

About the SPF Checker

How SPF works

SPF is a TXT record that lists the servers allowed to send mail for your domain. A receiver looks up the record for the domain in the message's envelope sender, works through it from left to right, and stops at the first term that matches the sending IP.

A typical record: v=spf1 include:_spf.google.com include:spf.privateemail.com ~all. Each include pulls in another provider's list. The final all decides what happens to every other server: ~all marks it suspicious, -all rejects it.

The 10-lookup limit

Receivers stop after 10 DNS lookups. include, a, mx, ptr, exists and redirect each cost one, and so does every lookup inside the records they include. Go over and SPF returns a permanent error, which most receivers treat as a fail for every message. Adding one more email service is the usual way people cross it without noticing.

To get back under: remove services you no longer use, replace a and mx with the ip4: and ip6: ranges they stand for, or move bulk senders to a subdomain with its own SPF.

One record only

A domain may have exactly one SPF record. Two TXT records that both start with v=spf1 make SPF fail. Merge them into one.

What it can't tell you

  • It checks the record, not a particular message. Whether a given email passes also depends on the server that sent it.
  • Macros (%{i} and similar) are counted but not expanded.

Frequently asked questions

Should I use ~all or -all?
Start with ~all while you confirm every service that sends for you, then move to -all. With DMARC at p=reject, the difference matters less, as DMARC decides the outcome.
What happens if SPF has more than 10 lookups?
Receivers return a permanent error (permerror). Most treat that like a fail, so legitimate mail can be rejected or sent to spam.
Does SPF protect the From address people see?
No. SPF checks the envelope sender (Return-Path). DMARC is what ties the result to the visible From address.
Can I have SPF on a subdomain?
Yes. Each host name that sends mail can have its own record, which is a good way to separate marketing mail from your main domain.

Your customers' VMs sending spam?

Frabs spots outbound spam from any VM within seconds and stops it, before your IPs end up on a blocklist.