Skip to content
FlexibleToolsAI
Security Toolkit · Free, Nothing Stored

SPF Record Checker

Look up and validate a domain's SPF record. The checker finds the v=spf1 TXT record, checks the syntax and the all mechanism, detects duplicate records, recursively resolves every include and redirect, and counts DNS lookups against SPF's hard limit of 10.

Enter a domain and we query its TXT records over DNS-over-HTTPS, parse the SPF record, and walk each include: and redirect= to count the DNS-querying mechanisms. Exceeding 10 lookups, having two SPF records, or ending with +all or ?all are flagged as failures, with the exact fix.

Instant Results

Live checks in seconds

Nothing Stored

No logs of what you check

No Sign-Up

Free, no credits or email

Suggest a Feature or Improvement for SPF Record Checker

Need custom options, higher limits, or extra format support? Let our engineering team know!

How to use SPF Record Checker

  1. 1Enter your domain.
  2. 2Check the record and the findings.
  3. 3Look at the include tree and lookup count.
  4. 4Fix errors in your DNS, then re-check.

The SPF rules that break most often

Only one SPF record is allowed — a second one makes SPF fail with a PermError. Evaluation may use at most 10 DNS lookups (include, a, mx, ptr, exists, redirect); adding several email providers often exceeds it. The record should end with ~all or -all; +all authorises the whole internet.

SPF checks the envelope sender, not the From address people see — so it only stops spoofing when combined with DMARC.

Fixing too many lookups

Remove includes for services you no longer use, replace some includes with the provider's ip4/ip6 ranges (SPF flattening, which needs maintenance), or send some mail from a subdomain with its own SPF record. Then set up DMARC and check DKIM.

Frequently Asked Questions

Should I use ~all or -all?

Both are fine with DMARC enforcing the policy. ~all (soft fail) is the common, safe default; -all is stricter.

Where do I add or edit the SPF record?

In your DNS provider (registrar, Cloudflare, Route 53…) as a TXT record on the root of your domain.

What do you do with the domains and URLs I check?

Our server performs the lookup once and returns the result to your browser. We don't store the addresses you check or build a history. Private and internal addresses are blocked.

Guides & Tutorials

Related Tools