Email sender authentication

📧 SPF Checker

Check any domain's SPF record, see every mechanism explained, and catch the too-many-lookups and weak-policy issues that break email authentication.

DNS lookup analysis Mechanism breakdown Security warnings

What is an SPF record?

An SPF (Sender Policy Framework) record is a DNS TXT record that lists which servers may send email for your domain. Receiving mail servers compare the sending server's IP address with this list. SPF is defined in RFC 7208.

SPF checks the envelope sender (the Return-Path address), not the From address people see in their inbox. To protect the visible From address, pair SPF with DMARC, which requires SPF or DKIM to pass for the same domain as the From header.

How to read an SPF record

v=spf1 include:_spf.google.com ip4:203.0.113.10 ~all

Receivers evaluate the terms left to right and stop at the first match. This example allows Google Workspace and one server at 203.0.113.10, and soft-fails everything else.

TermMeaningCounts toward the 10-lookup limit?
v=spf1Marks the record as SPF. Must come first.No
ip4: / ip6:An allowed IP address or range.No
include:Also allow whatever another domain's SPF record allows (how you authorise a provider).Yes, plus every lookup inside it
a / mxAllow the IPs of the domain's A record or its mail servers.Yes
exists:Advanced macro-based check.Yes
ptrReverse-DNS match. RFC 7208 says it SHOULD NOT be used: slow and unreliable.Yes
redirect=Use another domain's SPF record instead of this one.Yes
-allFail: anything not listed is unauthorised.No
~allSoftfail: not listed, probably unauthorised. Usually accepted but marked.No
?all / +allNeutral / allow everyone. Gives no protection; +all lets anyone send as you.No

SPF records for common email providers

Add the provider's include: to your single SPF record. Always confirm the value in your provider's own documentation, as they can change.

ProviderInclude to addExample record
Google Workspace / Gmailinclude:_spf.google.comv=spf1 include:_spf.google.com ~all
Microsoft 365 / Outlookinclude:spf.protection.outlook.comv=spf1 include:spf.protection.outlook.com -all
Zoho Mail (zoho.com)include:zoho.comv=spf1 include:zoho.com ~all
Zoho Mail (India, zoho.in)include:zoho.inv=spf1 include:zoho.in ~all
Amazon SESinclude:amazonses.comSet on your custom MAIL FROM subdomain so it aligns for DMARC
SendGridinclude:sendgrid.netUsually on the bounce subdomain SendGrid gives you
Mailguninclude:mailgun.orgv=spf1 include:mailgun.org ~all

Using two providers? Combine them in one record: v=spf1 include:_spf.google.com include:sendgrid.net ~all

Common SPF problems and how to fix them

ProblemWhat happensFix
More than 10 DNS lookupsPermError: many receivers ignore your SPF entirely.Remove includes for services you no longer use, replace small providers with their ip4: ranges, or send bulk mail from a subdomain with its own SPF record.
Two or more SPF recordsPermError: treated as no valid SPF.Merge every include: and ip4: into one v=spf1 record.
Ends with +all or ?allAnyone can pass, or no verdict at all.End with ~all, then -all once every sender is listed.
Uses ptrSlow, unreliable, costs a lookup.Replace with ip4:/ip6: or the provider's include.
An include domain has no SPF recordCounts as a "void lookup"; more than 2 void lookups is a PermError.Remove the include or correct the domain name.
Record longer than 255 characters in one stringDNS rejects or truncates it.Split it into several quoted strings in the same TXT record; receivers join them.
No SPF recordReceivers can't tell real mail from forged mail; deliverability suffers.Publish one TXT record at the root of the domain starting with v=spf1.
Domain that never sends email? Publish v=spf1 -all so nobody can send as it.

Frequently Asked Questions

What does this SPF checker do?

It fetches your domain's SPF TXT record, resolves every include and redirect, and counts the DNS lookups against the RFC limit of 10 so you can spot records that will fail.

Why does the 10-lookup limit matter?

SPF allows at most 10 DNS-querying mechanisms. Exceed it and many receivers return a PermError and ignore your SPF entirely, hurting deliverability. Flatten or remove unused includes to stay under it.

Should I end my SPF record with -all or ~all?

Use ~all (softfail) while you are still finding every service that sends mail for you, then switch to -all (fail) once the list is complete. Never use +all, and avoid ?all, which gives no protection.

Can a domain have two SPF records?

No. RFC 7208 allows exactly one TXT record starting with v=spf1. Two records cause a PermError, so receivers treat the domain as having no valid SPF. Merge them into one record.

Does SPF stop people spoofing my From address?

Not on its own. SPF checks the envelope sender (Return-Path), not the From address people see. DMARC ties SPF or DKIM to the visible From domain, so publish a DMARC record as well.

Is the SPF checker free and private?

Yes. Lookups run in your browser via public DNS-over-HTTPS and nothing is stored.

Pair SPF with DMARC for full protection · Last updated by Lazy Devs.