SPF record checker
An SPF check reads the domain's SPF TXT record and reports which servers it authorises to send mail and what should happen to everything else. The tool shows the raw record and flags the common faults: no record at all, two records, or a policy with no all mechanism.
Free, no account. Ten lookups a minute per IP.
How to read the record
A record like v=spf1 include:_spf.google.com ip4:203.0.113.5 ~all has three parts. The version tag is always first. The mechanisms in the middle authorise senders — include: delegates to another domain's record, ip4: and ip6: name addresses directly, a and mx authorise the domain's own hosts.
The final qualifier decides what happens to servers not on the list, and it is the part that carries the policy. -all is a hard fail, telling receivers to reject. ~all is a soft fail, meaning treat as suspicious but accept. ?all is neutral and provides almost nothing. +all authorises the entire internet and should never appear in a real record.
The ten-lookup limit
SPF permits a maximum of ten DNS lookups when evaluating a record, and each include:, a, mx, ptr and exists mechanism costs one. Chain too many and the whole record fails with a permanent error — receivers do not simply ignore the extras.
This is the most common way a working SPF record silently breaks. Adding a fifth or sixth email vendor is usually what pushes it over, and the symptom is authentication failures on mail that was fine last month. Flattening the record, or consolidating vendors, is the fix.
Why SPF alone is not enough
SPF validates the envelope sender, not the From address a recipient actually sees. A spammer can pass SPF for a domain they control while displaying yours in the From header, and SPF has no opinion about that at all.
It also breaks on forwarding: when a message is forwarded the sending IP changes, so SPF fails even though the mail is legitimate. DKIM survives forwarding, and DMARC is what ties either of them to the visible From address. All three together are the working configuration.
Common questions
- How do I check my SPF record?
- Paste your domain into the tool above. It looks up the TXT records, finds the one beginning v=spf1, shows the raw value, and reports whether the policy is strict, soft-fail, neutral or incomplete. You can also check any domain you do not control.
- What does ~all mean in an SPF record?
- It is a soft fail. Mail from a server not authorised by the record should be accepted but treated as suspicious, usually meaning it is more likely to be filed as spam. `-all` is the stricter form and asks receivers to reject outright; most organisations move from ~all to -all once they are confident every legitimate sender is listed.
- Can a domain have two SPF records?
- No. Publishing two records beginning v=spf1 is invalid and causes SPF evaluation to fail entirely, so the effect is worse than having one imperfect record. If you need to authorise an extra vendor, add its mechanism to the existing record rather than publishing a second one.
- What is the SPF ten-lookup limit?
- SPF allows at most ten DNS lookups per evaluation, and each include, a, mx, ptr and exists mechanism consumes one. Exceeding it makes the record fail with a permanent error rather than partially applying, and adding one vendor too many is the usual cause of SPF that worked until recently.
Check everything at once
This page covers one record. The full deliverability audit runs MX, SPF, DKIM, DMARC and blocklists together and scores the domain — or read the glossary entry for the concept behind this check.
You audited one domain. Cold outreach means thousands.
This tool checks a domain you type in. It will not tell you which addresses at that domain are real.
- Bulk mailbox verification with real SMTP checks
- The email finder — name plus company to a verified address
- Website enrichment for emails, owner names and socials
One plan, cancel anytime, no contract. The free tools stay free and unmetered either way — they are not a trial.