Back to Free Tools
SPF Record Checker
Inspect your SPF record for syntax errors, the 10-lookup limit, and the 'all' qualifier.
Check an SPF record
Try:
What is an SPF record?
An SPF (Sender Policy Framework) record is a DNS TXT record that tells receiving mail servers which IP addresses and hosts are allowed to send email on behalf of your domain. It is published at the root of your domain and evaluated on every inbound message.
A typical SPF record looks like this:
v=spf1 include:_spf.google.com include:mailgun.org ip4:198.51.100.0/24 ~allWhat this SPF checker validates
- Whether a
v=spf1record is published at the domain root - That only one SPF record exists (RFC 7208 forbids multiple)
- Syntax of every mechanism and modifier
- DNS lookup count against the 10-lookup limit (RFC 7208 §4.6.4)
- Void lookups against the 2-void-lookup limit
- The
allqualifier (-all,~all,?all,+all) - Deprecated mechanisms like
ptr - Redirect loops and conflicting modifiers
SPF mechanism reference
| Mechanism | Meaning | Counts toward 10-lookup limit |
|---|---|---|
all | Matches anything; always the last mechanism | No |
ip4: | Authorises an IPv4 address or CIDR range | No |
ip6: | Authorises an IPv6 address or CIDR range | No |
a | Matches the A/AAAA records of the domain | Yes (1) |
mx | Matches the MX hosts of the domain | Yes (1 + each MX) |
include: | Recursively evaluates another domain's SPF | Yes (1 + nested) |
exists: | Passes if a DNS A lookup of the macro resolves | Yes (1) |
redirect= | Replaces the current record with another domain's | Yes (1 + nested) |
ptr | Reverse-DNS check; deprecated and discouraged | Yes (slow) |
~all vs -all vs ?all
| Qualifier | Name | Effect |
|---|---|---|
-all | Hardfail | Receivers should reject mail from unlisted senders. Strongest. |
~all | Softfail | Receivers should accept but mark suspicious. Safe default. |
?all | Neutral | No assertion. Provides no protection. |
+all | Pass-all | Authorises everyone. Effectively disables SPF. Never use. |
How to fix the SPF 10-lookup limit
The 10-lookup limit is the most common cause of broken SPF in production. Going over it returns a permerror, which most receivers treat as a fail. Fix it by reducing the lookup count:
- Remove
include:entries for services you no longer use - Replace heavy includes with their published
ip4:/ip6:ranges where the vendor allows it - Consolidate subdomains under one record where possible
- Use a hosted SPF flattening service if your include chain is unavoidable
- Drop deprecated
ptrmechanisms entirely
Frequently asked questions
Related free tools
References
Go beyond one-off checks
Safer Sender continuously monitors your domain's DMARC, SPF and DKIM, classifies every sender, and guides you safely from p=none to p=reject.