Example SPF record
v=spf1 include:_spf.google.com include:sendgrid.net ip4:203.0.113.10 ~all
What the checker verifies
- Exactly one SPF record — two records cause a permanent error.
- The 10-lookup limit — include, a, mx, ptr, exists and redirect each cost a DNS lookup, including those inside included records. More than 10 makes SPF fail for every message.
- Void lookups — includes that point to domains without SPF (max 2).
- The all mechanism —
-all(fail) or~all(soft fail) protect you;?allis neutral and+alllets anyone send as you. - Deprecated or unknown mechanisms such as ptr.
Fixing "too many DNS lookups"
- Remove services you no longer use.
- Replace include: with ip4:/ip6: ranges where the provider publishes fixed IPs.
- Send marketing mail from a subdomain with its own SPF record.
Frequently asked questions
Should I use -all or ~all?
Both protect you. ~all (soft fail) is the safer choice while you confirm every sender; -all (hard fail) is stricter. DMARC decides the final action either way.
Can I have two SPF records?
No. Merge them into one record; two v=spf1 records cause a PermError and SPF fails.
Does SPF stop spoofing on its own?
Not fully. SPF checks the hidden envelope sender. DMARC is needed to protect the visible From address.

