$ tools

SPF record checker

Enter a domain to fetch its SPF record, follow every include and redirect, and count the DNS lookups the way a receiving server does. Past 10 lookups SPF returns a permanent error, and the record stops protecting anything.

What this checks

  • That the domain publishes exactly one SPF record, and that its syntax is valid.
  • The lookup count: every include, a, mx, ptr, exists and redirect, including the ones nested inside includes.
  • Void lookups: names that return nothing. More than two is a permanent error.
  • The all qualifier: +all lets any server pass, ?all is neutral.
  • The deprecated ptr mechanism.

Reading the include tree

Each line is one term that costs a lookup. The number beside it is what that term costs, including everything nested under it, so the largest number is the include to flatten or remove first. How to get back under the limit walks through the options.

Questions

Why does the limit of 10 lookups matter?

RFC 7208 caps the DNS lookups one SPF evaluation may make at 10. A receiver that reaches the cap stops and returns a permanent error, and DMARC treats that as an SPF failure for every message, not only the ones from the eleventh source.

Do ip4 and ip6 count toward the limit?

No. ip4, ip6 and all are matched without DNS. include, a, mx, ptr, exists and the redirect modifier each cost one lookup, and lookups inside an include count toward the same 10.

What is a void lookup?

A lookup that returns no records or finds that the domain does not exist. RFC 7208 lets a receiver fail SPF once there are more than two, so an include left behind for a provider you stopped using costs more than a lookup.

Checking a whole sending domain? The domain health check runs SPF, DKIM, DMARC, BIMI, MX and reverse DNS together.