How to use
Enter a domain or paste a record
Type example.com to check the published record. To test a change first, switch to Test a record, paste a draft that starts with v=spf1, and add the domain it is for.
Read the lookup count and checks
The cards show whether the record exists, how many of the 10 DNS lookups it uses and how many came back empty. The checks list explains each problem, and the include tree shows where lookups go.
Test a sending IP
Find the sending server's IP in a message's headers and enter it under Test a sending IP address. The result names the outcome and the mechanism that decided it.
Why SPF Record Checker
- Finds the SPF record, explains every mechanism, and counts DNS lookups against the limit of 10.
- Expands every include and redirect into a tree so you can see which service uses up lookups.
- Test a sending server's IP address and see the exact result: pass, fail, softfail or neutral.
- Paste a draft record to test it before you publish it, and copy the full list of allowed IP ranges.
SPF mechanisms and what they cost
An SPF record is read from left to right, and the first mechanism that matches decides the result. Each mechanism can carry a qualifier: + for pass (the default), - for fail, ~ for soft fail and ? for neutral.
| Term | What it matches | DNS lookups |
|---|---|---|
| ip4:203.0.113.0/24 | A single IPv4 address or range | 0 |
| ip6:2001:db8::/32 | A single IPv6 address or range | 0 |
| a | The domain's own A and AAAA addresses | 1 |
| mx | The domain's mail servers | 1, plus up to 10 MX host lookups |
| include:_spf.example.net | Anything another domain's SPF record passes | 1, plus everything inside |
| exists:%{i}.example.net | Any sender for which that name has an A record | 1 |
| ptr | Senders whose reverse DNS ends in the domain (deprecated) | 1 |
| redirect=_spf.example.net | Uses another domain's record when nothing matched | 1 |
| -all / ~all | Every sender not matched earlier | 0 |
Common SPF mistakes the checker catches
Most broken SPF records fail for one of a handful of reasons. Each one below appears in the checks list with a fix.
- Two SPF records, often after a new email service told you to add its own instead of editing yours.
- More than 10 lookups after years of adding includes for every new tool.
- An include that points at a domain with no SPF record, which makes the whole check a permerror.
- +all or ?all at the end, which gives away the protection SPF is meant to provide.
- Mechanisms placed after all, which receivers never reach.
- Typos such as ip4 addresses with a missing digit or an include without a colon.