SPF Record Checker

Analyze SPF records for email authentication

How to use SPF Record Checker

  1. 1Enter your domain name to query its published SPF DNS record.
  2. 2Enter the mail servers or include mechanisms you expect to see.
  3. 3Read the resolved SPF policy and whether it passes or has too many DNS lookups.

Validating SPF records

SPF = 'v=spf1 include:_spf.a include:_spf.b -all' (max 10 DNS-lookup mechanisms)

SPF tells receiving mail servers which IPs may send mail for your domain; a missing or broken record lets attackers spoof your address.

SPF allows at most 10 DNS lookups across all include mechanisms, so over-nesting includes causes permerror and mail may be rejected.

Frequently asked questions

What does -all mean?

A hard fail: reject mail from sources not in the policy. ~all is softfail, more permissive.

Why the 10-lookup limit?

To bound DNS query load; exceeding it yields permerror and receivers may reject.

Can SPF alone stop spoofing?

No, pair it with DKIM and DMARC for real protection and reporting.

More Tools