SPF record checker

Reads the live SPF record, resolves every include it points at, and counts the DNS lookups. Over ten, receivers stop evaluating your SPF entirely.

The ten-lookup limit is the one that catches people

RFC 7208 allows an SPF evaluation ten DNS lookups. Every include:, a, mx, ptr, exists: and redirect= costs one, and includes nest — adding your help desk, your CRM and your payroll provider can cross the line without any single record looking wrong. Past ten, a receiver returns permerror and ignores your SPF, so mail that would have passed starts failing. This tool resolves the includes and gives you the count.

Two SPF records is worse than none

A domain may publish exactly one v=spf1 record. With two, the result is a permanent error and receivers discard both, so the domain is treated as having no SPF at all. It happens when a record is added for a new sending tool instead of being merged into the existing one. We found a live example while sending outreach: simfolio.co publishes two.

What -all, ~all and +all actually do

-all tells receivers to reject anything from a server you have not listed. ~all asks them to accept it but mark it suspicious, which is the usual choice while you are still finding your senders. ?all is neutral and gives a receiver no reason to act. +all authorises the entire internet to send as your domain and should never be published.

Other checks

  • DMARC checkerReads the record at _dmarc on your domain and explains the policy it publishes — including the cases where a record exists but does nothing.
  • MX lookupResolves the MX records and names the provider behind them — which decides whether an address on this domain can be checked before you send to it.
  • Deliverability auditEvery check on this site at once, for a domain you are about to send from. It takes about a second and touches nothing but DNS.