SPF Record Checker
Look up and validate a domain's SPF record, count DNS lookups and explain every mechanism.
Continue your work
- DMARC Checker — Check the DMARC policy that uses SPF results.
- DKIM Checker — Check the other half of email authentication.
Share this tool
Found it useful? Send it to a friend or teammate.
Rate this tool
0.0
0 ratings
- 5 stars 0
- 4 stars 0
- 3 stars 0
- 2 stars 0
- 1 star 0
Clear instructions
Find steps, examples and limitations below.
Use online
Open the tool in a supported web browser.
Free to use
No sign-up required. Tool-specific limits may apply.
How to use the SPF Record Checker
Look up and validate a domain's SPF record, count DNS lookups and explain every mechanism.
- 1 Enter the domain you send email from.
- 2 Click Check SPF. Every include is followed so the total DNS lookup count is accurate.
- 3 Fix any failed checks, such as more than one SPF record, more than 10 lookups or a missing ~all or -all at the end.
Example and practical tips
A record like v=spf1 include:_spf.google.com include:sendgrid.net ~all passes when both services are used. If adding a fifth service pushes the count past 10 lookups, receivers return a PermError and SPF stops protecting you.
Frequently asked questions
What is the 10 DNS lookup limit?
SPF allows at most 10 mechanisms that need DNS lookups (include, a, mx, ptr, exists and redirect), counting nested includes. Going over makes SPF fail.
Should I use ~all or -all?
Start with ~all (soft fail) while you confirm every sender is listed, then move to -all (hard fail) for the strongest protection. Never use +all.
Can a domain have two SPF records?
No. Two v=spf1 TXT records cause a permanent error. Merge them into one record.
Report an issue
Something broken or not quite right? Tell us and we will look into it.