All tools

SPF Checker

Verify your SPF record in seconds. Free SPF checker runs a DNS lookup, validates the syntax and shows exactly which mail servers are authorized to send email for your domain.

Enter a domain - e.g. yourdomain.com

SPF record found

Whether a TXT policy exists for your domain

Policy syntax

Valid include and mechanism rules

Send authorized

Which servers may send email as you

No account required · Free · Results in under 1s

What is SPF?

SPF (Sender Policy Framework) tells receiving mail servers which IP addresses are allowed to send email for your domain.

SPF is an email authentication standard that protects your domain from spoofing. A domain owner publishes an SPF record as a DNS TXT record. This record lists the mail servers, IP addresses and third-party senders that are authorized to send email on behalf of the domain. When a message arrives, the receiving server looks up the SPF record and checks whether the sender's IP address is on the list.

If the IP address matches, the email passes the SPF check and is more likely to reach the inbox. If it does not match, the receiving server applies the policy of the record — usually a soft fail (~all) or a hard fail (-all) — and the message may be rejected or marked as spam. SPF works together with DKIM and DMARC: together these standards form the email authentication framework that makes spoofing and phishing much harder.

You can use an SPF checker before you publish a record, after you change a mail server, or when emails from your domain start landing in spam. The tool performs a DNS lookup for the TXT record, checks the SPF syntax, counts DNS lookups and flags common misconfigurations that break authentication — so you can fix your SPF record and protect your domain within minutes.

Get alerted when your SPF record breaks

The checker shows your email authentication today. Monitoring keeps testing your SPF, DKIM and DMARC records and notifies you when something changes or stops passing. No credit card required.

How to use the SPF checker

Check the SPF record of any domain in three simple steps.

  1. Enter your domain

    Type the domain name into the search field, for example yourcompany.com, and click the Check button. The tool runs a DNS lookup and finds the SPF record of the domain.

  2. Review the SPF record

    Read the record value that starts with v=spf1, the authorized IP addresses and the included third-party mail servers. The tool checks the syntax and shows the number of DNS lookups used by the record.

  3. Fix issues if any

    If the record is missing or contains errors, use the hints from the checker: add the missing include, fix the syntax, remove extra mechanisms or reduce the DNS lookup count to stay under the limit of 10.

Typical SPF issues and how to fix them

The most common problems found by an SPF record checker.

Missing SPF record

If a domain has no SPF record, receiving servers cannot verify its email, so messages are often rejected or flagged as spam. Publish a TXT record that starts with v=spf1, list your sending IP addresses and end with ~all or -all.

Publish a v=spf1 record

Publish a TXT record at the apex that starts with v=spf1, list your sending IP addresses and end with ~all or -all, then re-check the domain to confirm the record is live.

Too many DNS lookups

An SPF record can use no more than 10 DNS lookups, and every include, a or mx mechanism counts. When a record exceeds the limit, receivers return permerror and ignore the record. Remove or flatten unnecessary includes to keep the count low.

Flatten or reduce includes

Remove unused includes, replace nested includes with the provider's flattened record or list the IP addresses directly, and keep the lookup count below 10 so the record stays valid.

Syntax errors and permerror

A typo in a mechanism, an invalid IP address or a wrong qualifier makes the whole SPF record invalid. Use the checker to validate the syntax and confirm that the record starts with v=spf1 and uses only valid mechanisms like include, ip4, a, mx, redirect and exists.

Fix the syntax and validate

Correct the version tag, fix the mechanism qualifiers, remove duplicate mechanisms and re-check the domain until the record passes validation without permerror.

SPF fails for legitimate senders

When a trusted mail server's IP is missing from the record, its emails fail the SPF check and can be rejected. Add an include with the service's SPF record or list the exact IP address so every authorized sender passes the check.

Add the provider include

Insert the include mechanism from the email service documentation or add its sending IP range, wait for the DNS change to propagate, then run the SPF check again to confirm the sender is authorized.

What you get with SPF monitoring

Track every SPF change

Monitor your SPF record around the clock and see every change in one dashboard.

Instant alerts

Get notified by email or Telegram the moment your SPF record changes, breaks or stops passing.

Find issues faster

Instead of checking the record by hand, receive an instant report of any syntax error or missing include.

Protect your domain

Confirm that your domain stays protected from spoofing and phishing attacks at all times.

Global DNS checks

Verify how your SPF record is seen by DNS servers around the world after you publish it.

Free to start

Begin with a free plan and monitor your email authentication without paying anything.

Get alerted when your SPF record breaks

The checker shows your email authentication today. Monitoring keeps testing your SPF, DKIM and DMARC records and notifies you when something changes or stops passing. No credit card required.

SPF checker tips

Small habits that keep your email authenticated.

Tip #1 Publish one SPF record per domain

A domain can have only one SPF record. If a second record exists, receiving servers return permerror and ignore both. Use the checker to confirm that only one TXT record starts with v=spf1.

Tip #2 Count your DNS lookups

Every include, a or mx mechanism counts as a DNS lookup, and the limit is 10. If your record is close to the limit, flatten it or remove unused includes to keep it valid.

Show more tips Show less tips
Tip #3 Always end with ~all or -all

Without a catch-all qualifier at the end of the record, any server can send email for your domain. Use ~all for a soft fail while you test, and -all when you are sure about all your authorized senders.

Tip #4 Use include for third-party senders

When a service sends email for you, add its include mechanism instead of copying its whole record. This keeps your record short and lets the service update its own SPF record without your help.

Tip #5 Combine with DKIM and DMARC

SPF alone does not stop all spoofing. Add DKIM signatures and a DMARC policy so receiving servers can verify every message, and you can see who sends email for your domain.

Frequently asked questions

What is SPF?

SPF (Sender Policy Framework) is an email authentication standard. The domain owner publishes a DNS TXT record that lists the mail servers and IP addresses authorized to send email for the domain.

What is an SPF record?

An SPF record is a TXT record in DNS that starts with v=spf1 and contains mechanisms like include, ip4, a, mx and redirect, followed by an all qualifier such as ~all or -all. It tells receiving servers who is allowed to send email from your domain.

How does SPF work?

When an email arrives, the receiving mail server performs a DNS lookup for the sender domain's SPF record and compares the IP address of the sender with the addresses in the record. If there is a match, the message passes; if not, the policy in the record decides whether the email is rejected or marked as spam.

What is the difference between SPF, DKIM and DMARC?

SPF checks the sending IP address, DKIM verifies the digital signature of the message, and DMARC tells receiving servers what to do when SPF or DKIM fail. Together the three standards prevent spoofing and improve email deliverability.

Why do my emails go to spam?

A missing or broken SPF record is a common reason. Receiving servers cannot verify the sender, so they treat the email as suspicious. Check your SPF record, add missing includes and publish a DMARC policy to improve deliverability.

How do I check my SPF record?

Enter your domain in the SPF checker and run a DNS lookup. The tool shows the record value, checks the syntax, counts DNS lookups and flags issues such as missing includes or too many DNS lookups.

What does v=spf1 mean?

v=spf1 is the version tag that marks the beginning of an SPF record. Only a record that starts with v=spf1 is treated as a valid SPF record by receiving servers.

What is the 10 DNS lookup limit?

An SPF record may use at most 10 DNS lookups. Mechanisms like include, a and mx each add to the count. When a record exceeds the limit, receiving servers return permerror and ignore the record.

What does ~all mean in an SPF record?

~all is a soft fail qualifier. It tells receiving servers that only listed senders are legitimate, but messages from other servers should be accepted and marked as suspicious. Use -all for a hard fail, which rejects unlisted senders.

Can a domain have more than one SPF record?

No. A domain can have only one SPF record. If multiple records exist, receiving servers return permerror and authentication fails. Merge all records into a single value.

How do I fix an SPF error?

Use the SPF checker to find the problem: fix a wrong version tag, correct the syntax, remove duplicate mechanisms, reduce the DNS lookup count or add the missing include for your email service. Test the record again after every change.

Is the SPF checker free?

Yes. The SPF checker is free and unlimited — you can check any domain at any time. Monitoring plans add continuous tests and alerts if you need them.

Don't let broken email authentication hurt your deliverability

Run a free SPF check today and add monitoring to get alerts when your SPF, DKIM or DMARC record changes. Keep your email secure and out of spam.

Start monitoring free