Free SPF Checker Validate Your SPF Record

SPF tells receiving servers which senders may use your domain. Enter a domain to fetch its SPF record, verify there's exactly one, estimate its DNS lookup count, and check whether the all-mechanism policy (-all, ~all, +all) is safe.

How this check works

  1. 01

    TXT records are fetched and searched for a v=spf1 entry.

  2. 02

    The record is parsed for include:, a, mx, and ptr mechanisms to estimate the 10-lookup budget.

  3. 03

    The closing all-mechanism is graded: -all (strict, best), ~all (acceptable), +all (dangerous authorizes everyone).

How to fix common problems

Two SPF records

Having two v=spf1 TXT records makes SPF fail permanently. Merge all mechanisms into a single record.

Lookup count over 10

SPF allows 10 DNS lookups. Over that, receivers return PermError. Flatten includes or remove unused senders.

+all in the record

+all authorizes any server on the internet to send as your domain. Replace with -all or ~all immediately.

Example

'v=spf1 include:_spf.google.com include:sendgrid.net -all' uses 2 lookups, strict policy a healthy record for Google Workspace plus one ESP.

FAQ

What is an SPF record?
An SPF record is a DNS TXT entry listing which servers may send email for your domain. Receivers check it to reject spoofs.
What is the SPF 10-lookup limit?
SPF evaluation may perform at most 10 DNS lookups (includes, a, mx, ptr). Exceeding it returns PermError and mail fails authentication.
Should I use -all or ~all?
-all (hard fail) is the strongest and recommended once you're confident all senders are listed. ~all (soft fail) is safer while migrating.

Want this handled end-to-end?

We build and run the whole outbound system infrastructure, lists, and copy live in 10 days.

See the cold email system