SPF Record Checker

Look up a domain's SPF record, count its DNS lookups against the 10-lookup limit, and see exactly what to fix so your email stops landing in spam.

Bahasa Indonesia

Advertisement

How the SPF check works

The checker reads the TXT records published at your domain and picks the one that starts with v=spf1. It then follows every include: and redirect= the same way a receiving mail server would, and counts each mechanism that needs a DNS query: include, a, mx, ptr, exists, and redirect. Plain ip4 and ip6 entries are free. Nothing is stored; we only make public DNS queries.

Fixing the most common SPF errors

"Too many DNS lookups" (PermError)

Every marketing, helpdesk, and CRM tool asks you to add its own include, and each one can hide several more lookups inside it. Once the total passes 10, receivers stop evaluating and return PermError. To get back under the limit:

  • Remove includes for services you no longer use.
  • Drop a and mx if those servers never send mail, or replace them with their ip4 addresses.
  • Send bulk or marketing mail from a subdomain (for example news.example.com) with its own SPF record.

More than one SPF record

Adding a second v=spf1 record instead of editing the first is a very common mistake, and it breaks SPF for the whole domain. Merge them into one:

v=spf1 include:_spf.google.com include:sendgrid.net ~all

An include that no longer exists

If a provider retires the hostname you include, the lookup comes back empty and SPF fails with a PermError. Check the provider's current documentation and update or remove the include.

SPF is only one part of email authentication

Gmail and Yahoo now expect bulk senders to pass SPF and DKIM, and to publish a DMARC policy. SPF on its own does not protect the From address your readers see. After SPF is clean, run the DMARC Checker on the same domain.

Frequently asked questions

SPF (Sender Policy Framework) is a DNS TXT record that lists the servers allowed to send email for your domain. Receiving servers such as Gmail compare the sending IP against that list.

RFC 7208 caps the mechanisms that trigger DNS queries (include, a, mx, ptr, exists, redirect) at 10 per check. Going over the limit returns a PermError, and most receivers treat that as an SPF failure.

~all (softfail) is a safe choice while you are still finding every service that sends mail for you. Switch to -all (fail) once the record is complete. Never use +all.

No. A domain must publish exactly one record that starts with v=spf1. Merge every include into that single record.

No. SPF checks the hidden envelope sender, not the From address people see. Pair it with DKIM and a DMARC policy to protect the visible From domain.
Ad
Advertisement
Ad
Advertisement