SPF checker: is your SPF record valid?

Check that your SPF record exists, is written correctly and stays within the limit of 10 DNS lookups.

Enter a domain name or an email address, then run the check. Results appear after the form and are announced when they finish.

Reads public DNS records only.

How it works

Check your SPF record in seconds

Find out whether your SPF record is valid, which services it allows, and how close it is to the 10-lookup limit.

Enter your domain

Type the domain you send email from, or any email address at that domain.

We follow every include

The checker reads your record, follows each include and counts the DNS lookups a receiving server must make.

See what to fix

You get the full record, the include tree, the lookup count and a plain explanation of any problem.

Common SPF problems

What the SPF checker catches

Two SPF records

A domain may only have one. With two, SPF fails for every email.

Over 10 lookups

Too many includes make receivers treat SPF as failed, even for your real email.

Broken includes

Includes that point to a domain without an SPF record.

+all

A record that lets every server in the world send email as your domain.

Typos

Parts receivers cannot read, such as a missing colon or a misspelt mechanism.

Deprecated ptr

The slow ptr mechanism that some receivers ignore.

Good to know

Writing a good SPF record

01

One record per domain

Add every service that sends email for you (your mailbox provider, newsletter tool, website, CRM) to a single record.

02

Keep it under 10 lookups

Remove services you no longer use. For services with fixed addresses, ip4: and ip6: ranges cost no lookups.

03

End with ~all or -all

~all is the safe default with DMARC. -all is stricter. Never use +all.

More email tools

Check the rest of your email setup

Domain scanner

SPF, DKIM, DMARC, BIMI, mail servers and blocklists in one scan.

DKIM checker

Find your DKIM keys and check their length and format.

DMARC checker

See your DMARC policy, report addresses and next step.

BIMI checker

Check your logo record, SVG file and certificate.

Mail tester

Send one email and get a spam score out of 10.

Questions

SPF, explained

Something else? Get in touch and we’ll answer.

SPF (Sender Policy Framework) is a TXT record in your DNS that lists the servers allowed to send email for your domain. Receiving servers use it to spot forged email.

Each include, a, mx, ptr, exists and redirect in your record, and in the records it includes, costs one DNS lookup. SPF allows at most 10. Above that, receivers treat SPF as failed.

Both are fine. ~all (soft fail) marks unlisted senders as suspicious, and -all (hard fail) asks receivers to reject them. With DMARC in place, ~all is the most common choice. Never use +all.

No. A domain must have exactly one SPF record. With two, SPF fails. Combine them into one record with all the includes.

Try it

Is your SPF record working?

Check it now and see every include and lookup.