SPF Record Checker

Validate an SPF record, count DNS lookups (max 10) and see the full include tree.

What is an SPF record?

An SPF (Sender Policy Framework) record is a DNS TXT record that lists the mail servers allowed to send email for a domain. Receiving servers compare the sending server with this list to detect forged mail.

Example SPF record

v=spf1 include:_spf.google.com include:sendgrid.net ip4:203.0.113.10 ~all

What the checker verifies

  • Exactly one SPF record — two records cause a permanent error.
  • The 10-lookup limit — include, a, mx, ptr, exists and redirect each cost a DNS lookup, including those inside included records. More than 10 makes SPF fail for every message.
  • Void lookups — includes that point to domains without SPF (max 2).
  • The all mechanism — -all (fail) or ~all (soft fail) protect you; ?all is neutral and +all lets anyone send as you.
  • Deprecated or unknown mechanisms such as ptr.

Fixing "too many DNS lookups"

  1. Remove services you no longer use.
  2. Replace include: with ip4:/ip6: ranges where the provider publishes fixed IPs.
  3. Send marketing mail from a subdomain with its own SPF record.

Frequently asked questions

Should I use -all or ~all?

Both protect you. ~all (soft fail) is the safer choice while you confirm every sender; -all (hard fail) is stricter. DMARC decides the final action either way.

Can I have two SPF records?

No. Merge them into one record; two v=spf1 records cause a PermError and SPF fails.

Does SPF stop spoofing on its own?

Not fully. SPF checks the hidden envelope sender. DMARC is needed to protect the visible From address.