Free toolAPI available

SPF record checker

Look up and validate your domain's SPF record. Check syntax, count DNS lookups, trace nested includes, and find issues that can cause SPF authentication errors.

Loading tool access...

interacjohnsoncontrolsapolloverorbimercksalesforceworkdayatlassianpbstoyotaadobemediumcartaoptimizelysapxeroxassabloyenvatophilipstransunioninteracjohnsoncontrolsapolloverorbimercksalesforceworkdayatlassianpbstoyotaadobemediumcartaoptimizelysapxeroxassabloyenvatophilipstransunion

What the SPF checker analyzes

Every check turns the published policy into a structured report

Record configuration

Find the SPF TXT record and check its version, syntax, mechanisms, modifiers, and ending policy.

DNS lookup path

Expand includes and redirects, count DNS-querying terms, and identify errors in nested records.

Authorized sources

Show the domains, IP addresses, and networks that the published policy can authorize.

When to check an SPF record

When adding an email service

Confirm that the provider's include or IP ranges are published correctly without breaking the lookup limit.

After switching providers

Check that obsolete includes and authorized networks have been removed.

When email authentication fails

Look for syntax errors, broken dependencies, multiple records, and excessive DNS lookups.

Before stricter DMARC

Confirm legitimate services are included and their sender domains pass SPF and align where required.

What an SPF record can tell you

Which infrastructure may send

SPF mechanisms list IP addresses, networks, hosts, or external policies that may authorize sending servers.

Which services the domain depends on

Includes and redirects reveal external services whose DNS records affect the SPF result.

What happens to unmatched IPs

The matching mechanism's qualifier determines a pass, fail, softfail, or neutral result.

How SPF authentication works

1. The receiver identifies the sender

The receiving server obtains the connecting IP address and MAIL FROM domain.

2. The receiver looks up the policy

It queries that domain's TXT records and selects the SPF record beginning with v=spf1.

3. The receiver checks the mechanisms

Mechanisms are processed from left to right until one matches or evaluation returns an error.

Validate SPF records with our API

Signup for free and automate SPF checks

How to read an SPF record

v=spf1
Identifies the record as an SPF version 1 policy
include:
Evaluates another domain's SPF policy and matches if that policy returns pass
redirect=
Uses another domain's policy if no mechanism in the current record matches
ip4:
Authorizes an IPv4 address or network
ip6:
Authorizes an IPv6 address or network
a
Tests IP addresses published in a hostname's A or AAAA records
mx
Tests IP addresses associated with the domain's MX servers
exists:
Performs a macro-expanded DNS lookup and matches if an A record exists
all
Always matches and normally provides the final default result
+
Returns pass when the mechanism matches
-
Returns fail when the mechanism matches
~
Returns softfail when the mechanism matches
?
Returns neutral when the mechanism matches

The 10-lookup limit

SPF evaluation may use no more than 10 DNS-querying mechanisms and modifiers. The limit includes include, a, mx, ptr, exists, and redirect, including terms encountered inside nested records. The initial TXT lookup does not consume this budget, and ip4, ip6, and all do not count.

Common SPF issues

Too many DNS lookups

Nested include, a, mx, ptr, exists, and redirect terms can exceed the 10 DNS lookup limit.

Multiple SPF records

A domain may publish many TXT records, but only one SPF record beginning with v=spf1.

Broken or obsolete includes

Included domains without a valid SPF record can cause permanent SPF evaluation errors.

Overly broad authorization

Wide IP ranges, +all, or unnecessary includes can authorize more senders than intended.

Signup for testmail.app

Automate end-to-end email testing with our APIs.

FAQ

What is an SPF checker?

An SPF checker examines the email-sending policy published for a domain and reports whether it is configured correctly. It displays the SPF record, expands references to third-party services, identifies authorized IP addresses and networks, counts DNS lookups, and highlights errors or warnings.

How do I check an SPF record?

Enter the domain you want to check. The SPF checker will find its published record, expand included records, count DNS lookups, identify authorized sending services and IP ranges, and report any configuration issues. When investigating a specific email, check the domain shown in its Return-Path, which may differ from the visible From address.

What makes an SPF record valid?

A valid SPF record follows the required syntax, begins with v=spf1, and can be processed without exceeding SPF limits or encountering errors in referenced records. The domain must publish no more than one SPF record at the same DNS name, although it may have other TXT records for unrelated purposes. A technically valid record can still contain risky or unintended authorization, so warnings should also be reviewed.

What is the SPF 10 DNS lookup limit?

SPF evaluation may use no more than ten DNS-querying mechanisms and modifiers across the complete policy. The total includes lookups caused by include, a, mx, ptr, exists, and redirect, including those found in nested records. Mechanisms such as ip4, ip6, and all do not use the lookup budget. Exceeding the limit causes an SPF permanent error.

What do -all, ~all, ?all, and +all mean in an SPF record?

These endings describe how SPF should classify a sender that did not match an earlier mechanism. -all returns fail, ~all returns softfail, ?all returns neutral, and +all returns pass. Because all matches every remaining sender, it is normally placed last. A +all policy effectively authorizes any IP address and should generally be treated as a serious configuration issue.

Why can SPF pass while DMARC fails?

SPF can pass while DMARC fails when the domain authenticated by SPF does not match, or align with, the domain visible in the email’s From address. SPF usually checks the SMTP envelope-sender domain, while DMARC evaluates whether a passing SPF or DKIM identity aligns with the visible author domain. A passing SPF result alone is therefore not always enough for DMARC to pass.

Does a valid SPF record guarantee email delivery?

No, a valid SPF record does not guarantee that an email will be accepted or delivered to the inbox. SPF confirms whether an IP address is authorized to use a particular sending domain, but receiving systems may also consider DKIM, DMARC, sender reputation, message content, sending behavior, recipient preferences, and other anti-spam signals. A valid record also does not prove that every legitimate sender has been included or that every authorized source should still be trusted.