All tools

SPF Checker

Is your SPF record valid - see authorized senders before mail gets rejected or filtered.

Enter a domain - e.g. yourdomain.com

SPF record found

Whether a TXT policy exists for your domain

Policy syntax

Valid include and mechanism rules

Send authorized

Which servers may send email as you

No account required · Free · Results in under 1s

What is an SPF checker?

Email sender authentication explained

Missing or broken SPF records are a common reason legitimate email lands in spam - receivers cannot verify which servers may send as your domain.

An SPF checker reads the SPF TXT record and lists authorized senders, include lookups, and the fail policy (-all or ~all). A free SPF check helps you validate configuration after adding email tools.

Run a check after DNS changes or ESP onboarding. Add domains to TotalSiteControl monitoring for alerts when SPF records are modified or removed.

Get 30 monitors FREE

Start free monitoring with email alerts. No credit card required.

How to use the SPF Checker

Validate SPF email authentication records in under a minute - no account needed.

  1. Enter the domain

    Type the sending domain, for example yourdomain.com. That is the domain in your From addresses.

  2. Run the SPF check

    Click the check button. We look up the SPF TXT record and summarize mechanisms that authorize senders.

  3. Read the policy

    Confirm include/ip mechanisms cover every legitimate sender. Tighten or expand the record, then re-check.

Typical SPF issues and solutions

Authentication gaps that push mail to spam or cause rejects.

No SPF record

Receivers have no policy for your domain. Spoofing is easier and deliverability suffers.

Publish a starting SPF TXT

Add a TXT record at the apex with v=spf1 and your providers’ includes, ending in ~all or -all as appropriate, then re-check.

Too many DNS lookups

SPF exceeds the 10-lookup limit via nested includes. Receivers may treat SPF as failed.

Flatten or reduce includes

Remove unused senders, use provider-flattening guidance, and keep the lookup count under the limit.

Legitimate sender not listed

A new ESP or CRM sends mail that fails SPF because it is missing from the record.

Add the provider include

Insert the include or IP mechanism from the provider docs, wait for DNS, then verify with the SPF checker.

What you get with monitoring

Comprehensive data

Certificate, DNS, and reachability history in one place.

Trusted & accurate

Checks run from our servers - the same path users hit.

Fast & easy

Turn a one-off check into monitoring in under a minute.

Global coverage

External probes so internal network blind spots do not hide issues.

Instant alerts

Email and Telegram when something fails or is about to expire.

30 monitors free

Start free - no credit card required to begin monitoring.

Get 30 monitors FREE

Start free monitoring with email alerts. No credit card required.

SPF checker tips

Keep authorization tight without locking out real senders.

Tip #1 One SPF TXT at the apex

Multiple SPF TXT records break evaluation. Merge mechanisms into a single v=spf1 record.

Tip #2 Inventory every sending service

Marketing tools, ticketing, and transactional ESPs all need coverage.

Show more tips Show less tips
Tip #3 Move carefully from ~all to -all

Hard fail only after you confirm no legitimate path is missing.

Tip #4 Monitor SPF changes

Silent TXT edits break deliverability. Alerts on SPF changes are cheap insurance.

Frequently asked questions

What is an SPF checker?

It reads the SPF TXT record for a domain and shows which servers and services are authorized to send email on its behalf.

Is this SPF checker free?

Yes. Check any domain instantly - no signup, no credit card, and no limit on one-off checks.

What is an SPF record?

A DNS TXT record listing IP addresses and services allowed to send mail as your domain. It helps receivers detect spoofed messages.

Why are my emails going to spam?

Missing, invalid, or incomplete SPF records hurt authentication. Too many include lookups or a missing -all also reduce trust with receivers.

What does -all vs ~all mean in SPF?

-all is hard fail - unauthorized senders should be rejected. ~all is soft fail - mark suspicious. Use -all only when your SPF list is complete.

Can I have more than one SPF record?

No - only one SPF TXT record is allowed per domain. Merge all authorized senders into a single record.

Do I need DKIM and DMARC too?

SPF alone is not enough. Combine SPF, DKIM, and DMARC for the best protection against spoofing and spam filtering.

How often should I check SPF?

After adding email tools such as newsletters, CRM, or transactional ESPs. Monitoring catches accidental SPF changes.

Protect your email reputation

Monitor SPF, DKIM, and MX records with free alerts.

Start Monitoring Free