Email sender authentication
📧 SPF Checker
Check any domain's SPF record, see every mechanism explained, and catch the too-many-lookups and weak-policy issues that break email authentication.
What is an SPF record?
An SPF (Sender Policy Framework) record is a DNS TXT record that lists which servers may send email for your domain. Receiving mail servers compare the sending server's IP address with this list. SPF is defined in RFC 7208.
SPF checks the envelope sender (the Return-Path address), not the From address people see in their inbox. To protect the visible From address, pair SPF with DMARC, which requires SPF or DKIM to pass for the same domain as the From header.
How to read an SPF record
v=spf1 include:_spf.google.com ip4:203.0.113.10 ~all
Receivers evaluate the terms left to right and stop at the first match. This example allows Google Workspace and one server at 203.0.113.10, and soft-fails everything else.
| Term | Meaning | Counts toward the 10-lookup limit? |
|---|---|---|
| v=spf1 | Marks the record as SPF. Must come first. | No |
| ip4: / ip6: | An allowed IP address or range. | No |
| include: | Also allow whatever another domain's SPF record allows (how you authorise a provider). | Yes, plus every lookup inside it |
| a / mx | Allow the IPs of the domain's A record or its mail servers. | Yes |
| exists: | Advanced macro-based check. | Yes |
| ptr | Reverse-DNS match. RFC 7208 says it SHOULD NOT be used: slow and unreliable. | Yes |
| redirect= | Use another domain's SPF record instead of this one. | Yes |
| -all | Fail: anything not listed is unauthorised. | No |
| ~all | Softfail: not listed, probably unauthorised. Usually accepted but marked. | No |
| ?all / +all | Neutral / allow everyone. Gives no protection; +all lets anyone send as you. | No |
SPF records for common email providers
Add the provider's include: to your single SPF record. Always confirm the value in your provider's own documentation, as they can change.
| Provider | Include to add | Example record |
|---|---|---|
| Google Workspace / Gmail | include:_spf.google.com | v=spf1 include:_spf.google.com ~all |
| Microsoft 365 / Outlook | include:spf.protection.outlook.com | v=spf1 include:spf.protection.outlook.com -all |
| Zoho Mail (zoho.com) | include:zoho.com | v=spf1 include:zoho.com ~all |
| Zoho Mail (India, zoho.in) | include:zoho.in | v=spf1 include:zoho.in ~all |
| Amazon SES | include:amazonses.com | Set on your custom MAIL FROM subdomain so it aligns for DMARC |
| SendGrid | include:sendgrid.net | Usually on the bounce subdomain SendGrid gives you |
| Mailgun | include:mailgun.org | v=spf1 include:mailgun.org ~all |
Using two providers? Combine them in one record: v=spf1 include:_spf.google.com include:sendgrid.net ~all
Common SPF problems and how to fix them
| Problem | What happens | Fix |
|---|---|---|
| More than 10 DNS lookups | PermError: many receivers ignore your SPF entirely. | Remove includes for services you no longer use, replace small providers with their ip4: ranges, or send bulk mail from a subdomain with its own SPF record. |
| Two or more SPF records | PermError: treated as no valid SPF. | Merge every include: and ip4: into one v=spf1 record. |
| Ends with +all or ?all | Anyone can pass, or no verdict at all. | End with ~all, then -all once every sender is listed. |
| Uses ptr | Slow, unreliable, costs a lookup. | Replace with ip4:/ip6: or the provider's include. |
| An include domain has no SPF record | Counts as a "void lookup"; more than 2 void lookups is a PermError. | Remove the include or correct the domain name. |
| Record longer than 255 characters in one string | DNS rejects or truncates it. | Split it into several quoted strings in the same TXT record; receivers join them. |
| No SPF record | Receivers can't tell real mail from forged mail; deliverability suffers. | Publish one TXT record at the root of the domain starting with v=spf1. |
Frequently Asked Questions
What does this SPF checker do?
It fetches your domain's SPF TXT record, resolves every include and redirect, and counts the DNS lookups against the RFC limit of 10 so you can spot records that will fail.
Why does the 10-lookup limit matter?
SPF allows at most 10 DNS-querying mechanisms. Exceed it and many receivers return a PermError and ignore your SPF entirely, hurting deliverability. Flatten or remove unused includes to stay under it.
Should I end my SPF record with -all or ~all?
Use ~all (softfail) while you are still finding every service that sends mail for you, then switch to -all (fail) once the list is complete. Never use +all, and avoid ?all, which gives no protection.
Can a domain have two SPF records?
No. RFC 7208 allows exactly one TXT record starting with v=spf1. Two records cause a PermError, so receivers treat the domain as having no valid SPF. Merge them into one record.
Does SPF stop people spoofing my From address?
Not on its own. SPF checks the envelope sender (Return-Path), not the From address people see. DMARC ties SPF or DKIM to the visible From domain, so publish a DMARC record as well.
Is the SPF checker free and private?
Yes. Lookups run in your browser via public DNS-over-HTTPS and nothing is stored.
Pair SPF with DMARC for full protection · Last updated by Lazy Devs.