SPF record checker
Check any domain’s SPF record, count its DNS lookups against the 10-lookup limit, and catch +all, ?all, duplicate records and other errors. Free and instant.
Check an SPF record
Enter a domain to fetch its SPF record from public DNS and count every DNS lookup it needs, nested includes and all. You’ll also get DMARC and DKIM results and a score out of 100.
An SPF record is a single TXT record at your domain that starts with v=spf1 and lists the servers allowed to send mail for it. It must end with an all term and needs no more than 10 DNS lookups when it’s evaluated. The checker reads the record the way receiving mail servers do, follows every include: and redirect=, and tells you what to fix.
What the SPF checker looks at
| Check | What we look for | Why it matters |
|---|---|---|
| Record exists | A TXT record at the domain starting with v=spf1 | Without one, receivers can’t tell your servers from anyone else’s. |
| Only one record | Exactly one v=spf1 record | Two SPF records is a permanent error (permerror): SPF fails for all your mail. |
| The all qualifier | ~all or -all at the end | +all authorizes the whole internet; ?all never fails anyone. |
| DNS lookups | 10 or fewer, counted recursively through every include | Over 10 is a permerror, and SPF stops passing for all mail. |
| Broken includes | Every include: target returns an SPF record | A typo or retired include is an error, and empty answers count toward the void lookup limit. |
ptr | No ptr mechanism | RFC 7208 says not to use it: it’s slow, unreliable and some receivers skip it. |
redirect= | Followed and counted like an include | A redirect hands the whole policy to another record, including its all term. |
How SPF DNS lookups are counted
RFC 7208 limits SPF to 10 terms that cause DNS queries, so a receiver never does unbounded work for one message. The count covers the whole tree: an include that contains three more includes costs four lookups, not one.
| Term | Counts toward 10? | Notes |
|---|---|---|
include: | Yes, 1 each | Plus everything inside the included record. |
a | Yes, 1 | Looks up the A/AAAA records of your domain (or the one named). |
mx | Yes, 1 | Also resolves each MX host’s address; more than 10 MX hosts is an error on its own. |
ptr | Yes, 1 | Deprecated. Replace it with ip4/ip6 or an include. |
exists: | Yes, 1 | Used by some large senders (Salesforce, SparkPost) with macros. |
redirect= | Yes, 1 | Plus everything inside the target record. |
ip4:, ip6: | No | Addresses and CIDR ranges are free. |
all | No | The catch-all at the end. |
RFC 7208 also asks receivers to limit void lookups (queries that return no record at all) to two. Includes that point at domains which no longer publish SPF are the usual cause, which is why the checker flags includes that don’t resolve.
v=spf1 mx ip4:203.0.113.5 include:_spf.google.com include:sendgrid.net ~allOver the limit? How to fix “too many DNS lookups” covers removing unused senders, moving marketing mail to a subdomain and when flattening is safe. DMARC Dojo hosts your SPF record and refuses any change that would push it over 10 lookups, so the error can’t come back.
Reading the result
- Soft fail vs fail.
~alland-allboth count as an SPF fail for DMARC. Once DMARC is atp=reject, the choice matters much less. - SPF passing isn’t the same as DMARC passing. SPF checks the envelope sender (Return-Path). For DMARC, that domain must also match your From domain. Many email services use their own bounce domain, so they pass DMARC through DKIM instead. What SPF is and how it works explains the difference.
- Need a new record? The SPF record generator builds one from the services you use and shows the lookup count as you go.
Frequently asked questions
What happens if my SPF record has more than 10 lookups?
Receivers stop evaluating and return a permanent error (permerror). Most treat that as an SPF fail, so every message that relies on SPF for DMARC fails, not just mail from the service that tipped you over.
Can I have two SPF records if I use two email services?
No. Combine them into one record with an include: for each service, for example v=spf1 include:_spf.google.com include:sendgrid.net ~all. Two separate v=spf1 records is an error.
Does the SPF lookup limit apply to subdomains?
Each domain name has its own SPF record and its own 10-lookup budget. That’s why moving a marketing platform to a subdomain like news.example.com frees up lookups on your main domain.
Why does my SPF record pass here but DMARC still fails?
SPF can pass for the envelope sender domain while DMARC needs that domain to align with the From address. If a service bounces mail through its own domain, set up DKIM with your domain for it, or a custom Return-Path if the service offers one.
Should SPF end in ~all or -all?
Either works with DMARC, and both are far better than ?all or +all. ~all is the safer default while you’re still finding senders. See RFC 7208 section 2.6 for the exact results.