Check that your SPF record exists, is written correctly and stays within the limit of 10 DNS lookups.
Reads public DNS records only.
How it works
Find out whether your SPF record is valid, which services it allows, and how close it is to the 10-lookup limit.
Type the domain you send email from, or any email address at that domain.
The checker reads your record, follows each include and counts the DNS lookups a receiving server must make.
You get the full record, the include tree, the lookup count and a plain explanation of any problem.
Common SPF problems
A domain may only have one. With two, SPF fails for every email.
Too many includes make receivers treat SPF as failed, even for your real email.
Includes that point to a domain without an SPF record.
A record that lets every server in the world send email as your domain.
Parts receivers cannot read, such as a missing colon or a misspelt mechanism.
The slow ptr mechanism that some receivers ignore.
01
Add every service that sends email for you (your mailbox provider, newsletter tool, website, CRM) to a single record.
02
Remove services you no longer use. For services with fixed addresses, ip4: and ip6: ranges cost no lookups.
03
~all is the safe default with DMARC. -all is stricter. Never use +all.
More email tools
SPF, DKIM, DMARC, BIMI, mail servers and blocklists in one scan.
Find your DKIM keys and check their length and format.
See your DMARC policy, report addresses and next step.
Check your logo record, SVG file and certificate.
Send one email and get a spam score out of 10.
SPF (Sender Policy Framework) is a TXT record in your DNS that lists the servers allowed to send email for your domain. Receiving servers use it to spot forged email.
Each include, a, mx, ptr, exists and redirect in your record, and in the records it includes, costs one DNS lookup. SPF allows at most 10. Above that, receivers treat SPF as failed.
Both are fine. ~all (soft fail) marks unlisted senders as suspicious, and -all (hard fail) asks receivers to reject them. With DMARC in place, ~all is the most common choice. Never use +all.
No. A domain must have exactly one SPF record. With two, SPF fails. Combine them into one record with all the includes.
Try it
Check it now and see every include and lookup.
More tools: Website checker · DNS checker · Domain scanner · DKIM checker · DMARC checker · BIMI checker · Mail tester