Look up and validate your domain's SPF record. Check syntax, count DNS lookups, trace nested includes, and find issues that can cause SPF authentication errors.
Loading tool access...
Every check turns the published policy into a structured report
Find the SPF TXT record and check its version, syntax, mechanisms, modifiers, and ending policy.
Expand includes and redirects, count DNS-querying terms, and identify errors in nested records.
Show the domains, IP addresses, and networks that the published policy can authorize.
Confirm that the provider's include or IP ranges are published correctly without breaking the lookup limit.
Check that obsolete includes and authorized networks have been removed.
Look for syntax errors, broken dependencies, multiple records, and excessive DNS lookups.
Confirm legitimate services are included and their sender domains pass SPF and align where required.
SPF mechanisms list IP addresses, networks, hosts, or external policies that may authorize sending servers.
Includes and redirects reveal external services whose DNS records affect the SPF result.
The matching mechanism's qualifier determines a pass, fail, softfail, or neutral result.
The receiving server obtains the connecting IP address and MAIL FROM domain.
It queries that domain's TXT records and selects the SPF record beginning with v=spf1.
Mechanisms are processed from left to right until one matches or evaluation returns an error.
Signup for free and automate SPF checks
SPF evaluation may use no more than 10 DNS-querying mechanisms and modifiers. The limit includes include, a, mx, ptr, exists, and redirect, including terms encountered inside nested records. The initial TXT lookup does not consume this budget, and ip4, ip6, and all do not count.
Nested include, a, mx, ptr, exists, and redirect terms can exceed the 10 DNS lookup limit.
A domain may publish many TXT records, but only one SPF record beginning with v=spf1.
Included domains without a valid SPF record can cause permanent SPF evaluation errors.
Wide IP ranges, +all, or unnecessary includes can authorize more senders than intended.
Automate end-to-end email testing with our APIs.