SPF record checker
Enter a domain to fetch its SPF record, follow every include and redirect, and count the DNS lookups the way a receiving server does. Past 10 lookups SPF returns a permanent error, and the record stops protecting anything.
What this checks
- That the domain publishes exactly one SPF record, and that its syntax is valid.
- The lookup count: every
include,a,mx,ptr,existsandredirect, including the ones nested inside includes. - Void lookups: names that return nothing. More than two is a permanent error.
- The
allqualifier:+alllets any server pass,?allis neutral. - The deprecated
ptrmechanism.
Reading the include tree
Each line is one term that costs a lookup. The number beside it is what that term costs, including everything nested under it, so the largest number is the include to flatten or remove first. How to get back under the limit walks through the options.
Questions
Why does the limit of 10 lookups matter?
RFC 7208 caps the DNS lookups one SPF evaluation may make at 10. A receiver that reaches the cap stops and returns a permanent error, and DMARC treats that as an SPF failure for every message, not only the ones from the eleventh source.
Do ip4 and ip6 count toward the limit?
No. ip4, ip6 and all are matched without DNS. include, a, mx, ptr, exists and the redirect modifier each cost one lookup, and lookups inside an include count toward the same 10.
What is a void lookup?
A lookup that returns no records or finds that the domain does not exist. RFC 7208 lets a receiver fail SPF once there are more than two, so an include left behind for a provider you stopped using costs more than a lookup.
Checking a whole sending domain? The domain health check runs SPF, DKIM, DMARC, BIMI, MX and reverse DNS together.