Free SPF Checker Validate Your SPF Record
SPF tells receiving servers which senders may use your domain. Enter a domain to fetch its SPF record, verify there's exactly one, estimate its DNS lookup count, and check whether the all-mechanism policy (-all, ~all, +all) is safe.
How this check works
- 01
TXT records are fetched and searched for a v=spf1 entry.
- 02
The record is parsed for include:, a, mx, and ptr mechanisms to estimate the 10-lookup budget.
- 03
The closing all-mechanism is graded: -all (strict, best), ~all (acceptable), +all (dangerous authorizes everyone).
How to fix common problems
Two SPF records
Having two v=spf1 TXT records makes SPF fail permanently. Merge all mechanisms into a single record.
Lookup count over 10
SPF allows 10 DNS lookups. Over that, receivers return PermError. Flatten includes or remove unused senders.
+all in the record
+all authorizes any server on the internet to send as your domain. Replace with -all or ~all immediately.
Example
'v=spf1 include:_spf.google.com include:sendgrid.net -all' uses 2 lookups, strict policy a healthy record for Google Workspace plus one ESP.
FAQ
- What is an SPF record?
- An SPF record is a DNS TXT entry listing which servers may send email for your domain. Receivers check it to reject spoofs.
- What is the SPF 10-lookup limit?
- SPF evaluation may perform at most 10 DNS lookups (includes, a, mx, ptr). Exceeding it returns PermError and mail fails authentication.
- Should I use -all or ~all?
- -all (hard fail) is the strongest and recommended once you're confident all senders are listed. ~all (soft fail) is safer while migrating.
Related tools
Related resources
Want this handled end-to-end?
We build and run the whole outbound system infrastructure, lists, and copy live in 10 days.
See the cold email system