SPF record checker
Check a domain's SPF record, count its DNS lookups against the limit of 10, and see which include is using them up. Free, instant, no sign-up.
What this checks
- That there's exactly one SPF record, and that its syntax is valid
- DNS lookups used of the 10 allowed, with each include's cost in a tree
- Void lookups: includes that point at names with no records
- Includes that are missing, broken or loop back on themselves
- How the record ends: -all, ~all, or the risky ?all and +all
Or paste a record to check it before you publish
Nothing you paste is stored. Includes are looked up in public DNS.
An example, explained
v=spf1 include:spf.protection.outlook.com include:servers.mcsv.net ip4:192.0.2.10 -all
- include:
- Allows another domain's SPF senders. One lookup, plus whatever that record uses.
- ip4:
- Allows an address or range directly. No lookup.
- -all
- Everything not listed fails. ~all (soft fail) is also common.
Why SPF breaks, and how to read the result
SPF lists the servers allowed to send email as a domain. Receivers evaluate it from the top, and RFC 7208 caps the DNS lookups that takes at 10. Each include, a, mx, ptr, exists and redirect costs one, and so does everything inside each included record. ip4, ip6 and all cost nothing.
Too many lookups
Go over 10 and receivers return a permanent error (permerror): many treat the email as failing SPF, and DMARC fails with it unless DKIM passes. It happens quietly, usually when someone adds one more sending service. The include tree shows which branch costs the most, so you know what to remove or replace.
Other common failures
- Two SPF records: receivers ignore both. Merge them into one TXT record.
- A broken include: often a service you stopped using. Remove it.
- Void lookups: more than two names that don't exist is also a permanent error.
- +all or ?all: +all lets every server in the world send as the domain; ?all says nothing about unlisted senders. End with ~all or -all.
About flattening
Flattening replaces includes with the addresses they resolve to, which saves lookups. A flattened record copied by hand breaks the next time a provider changes its addresses, so this tool shows the analysis but doesn't hand out a static record. Hosted SPF flattens for you and re-checks every 6 hours. More in the guide to the SPF 10-lookup limit.
Do this for every client, every day
- All nine checks on every client domain, daily, graded A to F
- Alerts by email or webhook when a grade drops or a record changes
- A monthly report card for each client, with your logo on it
- Hosted DMARC, SPF, DKIM and MTA-STS, so fixes don't wait for a DNS login
Start a free 28-day trial: up to 3 domains, no card needed.
Keep going
- The SPF 10-lookup limit, and how to fix itThe guide
- DMARC checkerSee a domain's DMARC policy in plain English, and where its reports go.
- DKIM checkerFind a domain's DKIM keys, with or without the selector, and check their size.
- DMARC record generatorBuild a correct DMARC record in a minute, with each setting explained.
- Free domain checkerAll nine checks on a domain, with a grade from A to F.
- Report cardsWhat your clients get each month, with your logo on it.
Questions
What counts towards the 10-lookup limit?
Each include, a, mx, ptr, exists and redirect, including those inside the records you include. ip4, ip6 and all don't count.
What does SPF permerror mean?
The record can't be evaluated: usually more than 10 lookups, two SPF records, a syntax error or a broken include. Many receivers then treat the email as failing SPF.
Should I use ~all or -all?
Either is fine once DMARC is in place, because DMARC decides what happens to failing email. -all is stricter on its own; ~all is the usual choice while you're still finding every sender.
Can you give me a flattened record?
No, on purpose. A static flattened record goes stale when a provider changes its addresses, and email starts failing. Hosted SPF flattens and re-checks every 6 hours, so it stays correct.
Is the record I paste stored?
No. It's analysed in memory, its includes looked up in public DNS, and nothing is kept.
Know the day a client's SPF breaks.
Start a free 28-day trial: up to 3 domains, no card needed.