Skip to content

SPF Record Checker

Look up and validate a domain's SPF record, count DNS lookups and explain every mechanism.

Enter the domain you send email from. Every include is looked up to count the 10-lookup limit.

Continue your work

  • DMARC Checker — Check the DMARC policy that uses SPF results.
  • DKIM Checker — Check the other half of email authentication.

Share this tool

Found it useful? Send it to a friend or teammate.

Rate this tool

0.0

0 ratings

  • 5 stars 0
  • 4 stars 0
  • 3 stars 0
  • 2 stars 0
  • 1 star 0

Click a star to rate this tool

Clear instructions

Find steps, examples and limitations below.

Use online

Open the tool in a supported web browser.

Free to use

No sign-up required. Tool-specific limits may apply.

How to use the SPF Record Checker

Look up and validate a domain's SPF record, count DNS lookups and explain every mechanism.

  1. 1 Enter the domain you send email from.
  2. 2 Click Check SPF. Every include is followed so the total DNS lookup count is accurate.
  3. 3 Fix any failed checks, such as more than one SPF record, more than 10 lookups or a missing ~all or -all at the end.

Example and practical tips

A record like v=spf1 include:_spf.google.com include:sendgrid.net ~all passes when both services are used. If adding a fifth service pushes the count past 10 lookups, receivers return a PermError and SPF stops protecting you.

Frequently asked questions

What is the 10 DNS lookup limit?

SPF allows at most 10 mechanisms that need DNS lookups (include, a, mx, ptr, exists and redirect), counting nested includes. Going over makes SPF fail.

Should I use ~all or -all?

Start with ~all (soft fail) while you confirm every sender is listed, then move to -all (hard fail) for the strongest protection. Never use +all.

Can a domain have two SPF records?

No. Two v=spf1 TXT records cause a permanent error. Merge them into one record.

Report an issue

Something broken or not quite right? Tell us and we will look into it.