SPF record checker

See which services may send email on your behalf, whether your record is valid, and how close you are to the 10-lookup limit.

How the SPF check works

We fetch the TXT record starting v=spf1 at your domain, then follow every include:, redirect=, a, mx and exists: to build the full tree of approved senders. Each step that needs another DNS query counts towards the limit of 10 set by the SPF standard (RFC 7208). We count the way receiving servers do, through every nested include, so the number matches what Gmail and Microsoft see.

Common SPF errors and what they mean

  • Too many DNS lookups (permerror). The record needs more than 10 lookups, so inboxes treat SPF as broken. See how to get back under the limit.
  • Multiple SPF records. Two TXT records starting v=spf1 invalidate each other. Merge them into one.
  • Include not found. An include: points at a domain with no SPF record, often a typo or a service you no longer use.
  • Too many void lookups. More than two lookups that return nothing also break SPF.
  • +all at the end. This authorises any server on the internet, so the record offers no protection.
  • Using ptr. Outdated, slow and discouraged by the standard. Remove it.

SPF on its own isn’t enough

SPF checks the hidden return address, not the From address people see, and it usually fails when email is forwarded. That’s why it works together with DKIM and DMARC. Use the SPF record builder to put together a corrected record, or read how the three fit together.

What is SPF, in plain English?

It’s a public list of the services allowed to send email using your domain, published as a TXT record. Inboxes check it to decide whether a message claiming to be from you is genuine.

Why is there a 10-lookup limit?

Every “include” makes the inbox look up another record, and some of those include more. Past 10 lookups, inboxes stop checking and treat your SPF record as broken, so your email can land in spam.

Can I have two SPF records?

No. If your domain publishes more than one record starting with v=spf1, inboxes ignore all of them. Merge everything into a single record.

Should it end with ~all or -all?

Both are fine when you also have DMARC. ~all marks unlisted senders as suspicious; -all tells inboxes to reject them. Never use +all, which authorises any server on the internet.