Is your SPF record valid - see authorized senders before mail gets rejected or filtered.
We'll send a summary for your target only. Unsubscribe anytime.
Whether a TXT policy exists for your domain
Valid include and mechanism rules
Which servers may send email as you
No account required · Free · Results in under 1s
Email sender authentication explained
Missing or broken SPF records are a common reason legitimate email lands in spam - receivers cannot verify which servers may send as your domain.
An SPF checker reads the SPF TXT record and lists authorized senders, include lookups, and the fail policy (-all or ~all). A free SPF check helps you validate configuration after adding email tools.
Run a check after DNS changes or ESP onboarding. Add domains to TotalSiteControl monitoring for alerts when SPF records are modified or removed.
Start free monitoring with email alerts. No credit card required.
Validate SPF email authentication records in under a minute - no account needed.
Type the sending domain, for example yourdomain.com. That is the domain in your From addresses.
Click the check button. We look up the SPF TXT record and summarize mechanisms that authorize senders.
Confirm include/ip mechanisms cover every legitimate sender. Tighten or expand the record, then re-check.
Authentication gaps that push mail to spam or cause rejects.
Receivers have no policy for your domain. Spoofing is easier and deliverability suffers.
Add a TXT record at the apex with v=spf1 and your providers’ includes, ending in ~all or -all as appropriate, then re-check.
SPF exceeds the 10-lookup limit via nested includes. Receivers may treat SPF as failed.
Remove unused senders, use provider-flattening guidance, and keep the lookup count under the limit.
A new ESP or CRM sends mail that fails SPF because it is missing from the record.
Insert the include or IP mechanism from the provider docs, wait for DNS, then verify with the SPF checker.
Certificate, DNS, and reachability history in one place.
Checks run from our servers - the same path users hit.
Turn a one-off check into monitoring in under a minute.
External probes so internal network blind spots do not hide issues.
Email and Telegram when something fails or is about to expire.
Start free - no credit card required to begin monitoring.
Start free monitoring with email alerts. No credit card required.
Keep authorization tight without locking out real senders.
Multiple SPF TXT records break evaluation. Merge mechanisms into a single v=spf1 record.
Marketing tools, ticketing, and transactional ESPs all need coverage.
Hard fail only after you confirm no legitimate path is missing.
Silent TXT edits break deliverability. Alerts on SPF changes are cheap insurance.
It reads the SPF TXT record for a domain and shows which servers and services are authorized to send email on its behalf.
Yes. Check any domain instantly - no signup, no credit card, and no limit on one-off checks.
A DNS TXT record listing IP addresses and services allowed to send mail as your domain. It helps receivers detect spoofed messages.
Missing, invalid, or incomplete SPF records hurt authentication. Too many include lookups or a missing -all also reduce trust with receivers.
-all is hard fail - unauthorized senders should be rejected. ~all is soft fail - mark suspicious. Use -all only when your SPF list is complete.
No - only one SPF TXT record is allowed per domain. Merge all authorized senders into a single record.
SPF alone is not enough. Combine SPF, DKIM, and DMARC for the best protection against spoofing and spam filtering.
After adding email tools such as newsletters, CRM, or transactional ESPs. Monitoring catches accidental SPF changes.