SPF Record Checker
Analyze SPF records for email authentication
How to use SPF Record Checker
- 1Enter your domain name to query its published SPF DNS record.
- 2Enter the mail servers or include mechanisms you expect to see.
- 3Read the resolved SPF policy and whether it passes or has too many DNS lookups.
Validating SPF records
SPF = 'v=spf1 include:_spf.a include:_spf.b -all' (max 10 DNS-lookup mechanisms)SPF tells receiving mail servers which IPs may send mail for your domain; a missing or broken record lets attackers spoof your address.
SPF allows at most 10 DNS lookups across all include mechanisms, so over-nesting includes causes permerror and mail may be rejected.
Frequently asked questions
What does -all mean?
A hard fail: reject mail from sources not in the policy. ~all is softfail, more permissive.
Why the 10-lookup limit?
To bound DNS query load; exceeding it yields permerror and receivers may reject.
Can SPF alone stop spoofing?
No, pair it with DKIM and DMARC for real protection and reporting.
