My Tool Studio
Webmaster

SPF Record Checker

An SPF record checker reads a domain's SPF record and tells you whether it will actually work. Enter a domain or email address and press Check SPF. The tool finds the v=spf1 record, explains each mechanism in plain English, and follows every include and redirect to count DNS lookups against the limit of 10, which is where many SPF records quietly break. An include tree shows which service uses up your lookups, and the checks flag multiple SPF records, +all, a missing all, ptr, empty lookups, loops and syntax errors. Type a sending server's IP address to see the exact result it would get, pass, fail, softfail or neutral, and which mechanism decided it. You can also paste a draft record to test before you publish, and copy the full list of allowed IP ranges.

Always freeNo sign upRuns in your browser

How to use

01

Enter a domain or paste a record

Type example.com to check the published record. To test a change first, switch to Test a record, paste a draft that starts with v=spf1, and add the domain it is for.

02

Read the lookup count and checks

The cards show whether the record exists, how many of the 10 DNS lookups it uses and how many came back empty. The checks list explains each problem, and the include tree shows where lookups go.

03

Test a sending IP

Find the sending server's IP in a message's headers and enter it under Test a sending IP address. The result names the outcome and the mechanism that decided it.

Why SPF Record Checker

SPF mechanisms and what they cost

An SPF record is read from left to right, and the first mechanism that matches decides the result. Each mechanism can carry a qualifier: + for pass (the default), - for fail, ~ for soft fail and ? for neutral.

TermWhat it matchesDNS lookups
ip4:203.0.113.0/24A single IPv4 address or range0
ip6:2001:db8::/32A single IPv6 address or range0
aThe domain's own A and AAAA addresses1
mxThe domain's mail servers1, plus up to 10 MX host lookups
include:_spf.example.netAnything another domain's SPF record passes1, plus everything inside
exists:%{i}.example.netAny sender for which that name has an A record1
ptrSenders whose reverse DNS ends in the domain (deprecated)1
redirect=_spf.example.netUses another domain's record when nothing matched1
-all / ~allEvery sender not matched earlier0

Common SPF mistakes the checker catches

Most broken SPF records fail for one of a handful of reasons. Each one below appears in the checks list with a fix.

  • Two SPF records, often after a new email service told you to add its own instead of editing yours.
  • More than 10 lookups after years of adding includes for every new tool.
  • An include that points at a domain with no SPF record, which makes the whole check a permerror.
  • +all or ?all at the end, which gives away the protection SPF is meant to provide.
  • Mechanisms placed after all, which receivers never reach.
  • Typos such as ip4 addresses with a missing digit or an include without a colon.

Common questions

What does an SPF record do?
SPF, the Sender Policy Framework, is a TXT record that lists the servers allowed to send email for your domain. Receiving servers compare the sending IP with that list and record a pass or fail. On its own SPF does not decide delivery, but DMARC and spam filters rely on it.
What is the SPF limit of 10 DNS lookups?
While checking a record, a receiver may make at most 10 DNS lookups. Every include, a, mx, ptr, exists and redirect costs one, including those inside included records. ip4, ip6 and all cost nothing. Go over 10 and the result is permerror, which most receivers treat as a failed SPF check.
How do I fix an SPF record that has too many lookups?
Remove includes for services you no longer use, replace a and mx with fixed ip4 ranges if your servers never change, and move marketing or ticketing tools to a subdomain with its own SPF record. Flattening includes into IP ranges also works, but those lists go stale when providers change them.
Should an SPF record end with ~all or -all?
Use ~all (soft fail) while you are still finding every service that sends for you, then -all (hard fail) once you are sure. With DMARC in place, receivers act on the DMARC policy either way. Never use +all, which allows any server in the world, and avoid ?all, which gives no protection.
Can a domain have two SPF records?
No. With more than one TXT record starting with v=spf1, receivers return permerror and SPF fails for every message. Merge them into one record, with all the include and ip4 terms together and a single all at the end.
What is the difference between include and redirect in SPF?
include asks another domain's SPF record whether it passes, and if not, carries on with the rest of your record. redirect hands the whole decision to another domain's record, and only applies when nothing else in your record matched. Use redirect when several domains share one policy.
Why does SPF pass but DMARC still fail?
SPF checks the envelope sender, the Return-Path domain, which a mailing service often sets to its own domain. DMARC also needs that domain to match the From address people see. If it does not align, DMARC relies on DKIM instead, so set up DKIM signing with your own domain at each service.
What is SPF flattening, and is it safe?
Flattening replaces include terms with the IP ranges they currently contain, which cuts lookups. It is safe only if you keep the list up to date, because providers add and change ranges without notice and your mail then fails SPF. The allowed IP ranges list here is a good starting point for checking.
Does a domain that sends no email need an SPF record?
Yes, a simple one. Publish v=spf1 -all on domains and subdomains that never send mail, so spammers cannot pass SPF while pretending to be you. Pair it with a DMARC record set to p=reject for full effect.

More Webmaster tools

View all