Free tool
SPF record checker
Enter a domain to read its SPF record, follow every include and count DNS lookups against the limit of 10. You get a verdict and the exact fix for each issue.
Quick answer
What this tool checks
Exactly one SPF record. Two v=spf1 records on the same domain are a permanent error. Receivers stop evaluating SPF entirely.
DNS lookup count. include, a, mx, ptr, exists and redirect each cost a lookup, including those inside included records. We follow them recursively, stop at the limit and detect include loops.
The all mechanism. We read how the record ends: -all and ~all protect you, ?all is neutral, +all lets anyone send as you, and no all at all defaults to neutral.
Broken includes and deprecated terms. Includes pointing at domains without an SPF record, unknown mechanisms and the deprecated ptr mechanism are all flagged.
What each ending means
| Ending | Result for unlisted servers | Use it when |
|---|---|---|
| -all | Fail | You know every service that sends for you |
| ~all | Soft fail | Default choice, alongside DMARC |
| ?all | Neutral | Rarely useful: says nothing |
| +all | Pass | Never: anyone can send as your domain |
How to fix common issues
Too many DNS lookups
Remove includes for services you no longer use first. Then replace a and mx with the ip4 or ip6 ranges they resolve to, or move one sender to a subdomain with its own SPF record. Avoid flattening tools that hardcode provider IPs unless they keep them updated.
Multiple SPF records
Merge them: keep one v=spf1, put every include and ip4/ip6 from both records in it, and end with a single all. Delete the other TXT record.
+all or ?all
Change the ending to ~all. Once DMARC reports show all your legitimate mail passing, you can move to -all.
Your email provider is missing
Add the include your provider documents, for example include:amazonses.com for Amazon SES. With a custom MAIL FROM domain, SPF is checked on that subdomain, which is how Lumail sets it up for you.
Frequently asked questions
What is the SPF 10 DNS lookup limit?
RFC 7208 caps SPF evaluation at 10 DNS-querying terms: include, a, mx, ptr, exists and redirect, counted across every nested include. Past 10, receivers return a permanent error and SPF fails for all your mail.
Should I use ~all or -all?
Both are fine with DMARC in place, since DMARC decides what happens to failing mail. ~all is the safer default while you are still discovering senders. -all is stricter once you are sure the record is complete.
Can a domain have two SPF records?
No. With more than one v=spf1 TXT record, receivers return a permanent error and treat SPF as failed. Merge everything into one record.
Does SPF alone stop spoofing?
No. SPF checks the hidden envelope sender, not the From address people see. You need DKIM and a DMARC policy to protect the visible From domain.
Does this tool contact my mail server?
No. It only reads public TXT records from DNS, with a timeout on each query. Nothing is sent to the domain.
Related tools and guides
- GlossaryWhat is SPF?How receivers check which servers may send for a domain.
- GlossaryWhat is DMARC?The policy that ties SPF and DKIM to your From domain.
- DocsAuthenticate a sending domainSet up SPF, DKIM and DMARC for Lumail.
- Free toolDKIM checkerFind a domain’s DKIM keys by selector.
- Free toolDMARC checkerRead the DMARC policy and what to tighten.
- Free toolMail testerSend a real email and get a score out of 10.
Authenticated sending, set up for you.
3,000 emails a month free. Unlimited subscribers on every plan. Campaigns, automations and transactional email on one domain.