Skip to main content
WebTools

SPF record checker

Check that a domain's SPF record is valid, stays within the 10-lookup limit, and says what you expect about servers that may send its mail.

Choosing a check opens its page. With the keyboard, use the arrow keys, then press Enter.

What we check

SPF (Sender Policy Framework, RFC 7208) is a TXT record that lists the servers allowed to send email for a domain. We fetch the record, check its syntax term by term, and follow every include to count DNS lookups the way receivers do. We check the published policy only; we don't test a particular sending server.

The limits receivers apply

The "all" setting

"-all" fails mail from servers not listed, "~all" marks it as a soft fail, and "?all" is neutral. "+all" lets any server send as the domain. Which is right depends on how you use DMARC and how sure you are that every sending service is listed.

Frequently asked questions

What is the 10-lookup limit?

Receivers stop evaluating SPF after 10 DNS lookups, counting include, a, mx, ptr, exists and redirect terms in the record and in every record it includes. Going over gives a permanent error, so SPF fails for all mail. We count through the whole include tree.

Should I use -all or ~all?

Both are common. "-all" asks receivers to fail mail from servers not listed; "~all" asks them to treat it as suspicious. Many domains use "~all" while they check that every sending service is listed, and DMARC usually decides what happens in the end. We describe what each setting does rather than say one is always right.

Can a domain have two SPF records?

No. With more than one, receivers return a permanent error and ignore them all. Merge them into a single record that starts with v=spf1.

What is a void lookup?

A lookup that finds nothing: a name that doesn't exist or has no records of the type asked for. Receivers allow at most two, to protect themselves from badly written records.

Do you test whether a particular server may send?

No. This checks the published policy, the way the major SPF validators do. Testing a specific sending IP needs a message, so it isn't part of this check.

  • DMARC Checker

    Find the DMARC policy that applies to a domain, see what each setting means, and spot mistakes that make receivers ignore it.

  • MX Lookup

    See which mail servers receive email for a domain, in priority order, with each server's addresses.

  • DNS Lookup

    Look up the DNS records published for a domain, one type or all common types at once, or the reverse DNS name of an IP address.

  • HTTP Header Checker

    See the HTTP status and every response header a website sends, for the final page and each redirect on the way.

  • Redirect Checker

    Follow a web address through every redirect, with the status code, destination and timing of each hop.

  • Website Health Check

    Run the main website, DNS and email checks on one site at once and get a short report, area by area, with links to the full results.