Back to Free Tools

    SPF Record Checker

    Inspect your SPF record for syntax errors, the 10-lookup limit, and the 'all' qualifier.

    Check an SPF record

    Try:

    What is an SPF record?

    An SPF (Sender Policy Framework) record is a DNS TXT record that tells receiving mail servers which IP addresses and hosts are allowed to send email on behalf of your domain. It is published at the root of your domain and evaluated on every inbound message.

    A typical SPF record looks like this:

    v=spf1 include:_spf.google.com include:mailgun.org ip4:198.51.100.0/24 ~all

    What this SPF checker validates

    • Whether a v=spf1 record is published at the domain root
    • That only one SPF record exists (RFC 7208 forbids multiple)
    • Syntax of every mechanism and modifier
    • DNS lookup count against the 10-lookup limit (RFC 7208 §4.6.4)
    • Void lookups against the 2-void-lookup limit
    • The all qualifier (-all, ~all, ?all, +all)
    • Deprecated mechanisms like ptr
    • Redirect loops and conflicting modifiers

    SPF mechanism reference

    MechanismMeaningCounts toward 10-lookup limit
    allMatches anything; always the last mechanismNo
    ip4:Authorises an IPv4 address or CIDR rangeNo
    ip6:Authorises an IPv6 address or CIDR rangeNo
    aMatches the A/AAAA records of the domainYes (1)
    mxMatches the MX hosts of the domainYes (1 + each MX)
    include:Recursively evaluates another domain's SPFYes (1 + nested)
    exists:Passes if a DNS A lookup of the macro resolvesYes (1)
    redirect=Replaces the current record with another domain'sYes (1 + nested)
    ptrReverse-DNS check; deprecated and discouragedYes (slow)

    ~all vs -all vs ?all

    QualifierNameEffect
    -allHardfailReceivers should reject mail from unlisted senders. Strongest.
    ~allSoftfailReceivers should accept but mark suspicious. Safe default.
    ?allNeutralNo assertion. Provides no protection.
    +allPass-allAuthorises everyone. Effectively disables SPF. Never use.

    How to fix the SPF 10-lookup limit

    The 10-lookup limit is the most common cause of broken SPF in production. Going over it returns a permerror, which most receivers treat as a fail. Fix it by reducing the lookup count:

    • Remove include: entries for services you no longer use
    • Replace heavy includes with their published ip4: / ip6: ranges where the vendor allows it
    • Consolidate subdomains under one record where possible
    • Use a hosted SPF flattening service if your include chain is unavoidable
    • Drop deprecated ptr mechanisms entirely

    Frequently asked questions

    References

    Go beyond one-off checks

    Safer Sender continuously monitors your domain's DMARC, SPF and DKIM, classifies every sender, and guides you safely from p=none to p=reject.