SPF check: validate your SPF record
Enter a domain and see its SPF record taken apart: every include followed, the DNS lookups counted, and the mistakes that make receivers ignore it. Add an IP address to test whether it may send mail for the domain.
What the SPF check covers
- The record itself
- Whether the domain has exactly one SPF record and every term in it is valid.
- The 10-lookup limit
- How many DNS lookups evaluating the record needs. Above ten, receivers give up and SPF fails for all mail.
- Includes and redirects
- The records your record pulls in from mail providers, shown as a tree, and whether each of them exists.
- The policy
- What happens to mail from servers you did not list: rejected (-all), marked suspicious (~all) or let through.
- Authorized senders
- Every address and network that ends up allowed to send mail for the domain.
- A single sender
- Whether one specific IP address would pass, and which term decides it.
Frequently asked questions
What is an SPF record?
A TXT record in the domain's DNS that lists which servers may send mail using the domain as sender. Receiving servers compare the sending server's address with that list.
Why does SPF fail although my record looks right?
The most common cause is the limit of ten DNS lookups: every include, a, mx and redirect counts, including those inside the records you include. Above ten the whole record is ignored. Having two SPF records has the same effect.
Should the record end with "-all" or "~all"?
Both tell receivers that unlisted servers are not allowed. "-all" asks them to reject such mail, "~all" to accept it as suspicious. With a DMARC policy in place the two are equally effective, and "~all" is the safer choice while you are still finding all your sending services.
Is SPF enough on its own?
No. SPF checks the envelope sender, which the recipient never sees. Only together with DKIM and a DMARC policy does it protect the visible From address.