Suped

SPF checker

Look up your SPF DNS records and analyze for errors.

Check your SPF record is valid and correct

Live DNS lookup
Run a live SPF DNS lookup to verify the record receivers use, catch syntax issues, and check whether your domain stays within SPF limits. For ongoing management, use Suped's hosted SPF and SPF flattening to keep records accurate and within lookup limits as providers change. For background, review the SPF lookup limit and SPF TXT formatting guide.
Get started
outcome left image

One SPF checker, endless uses

Use the SPF checker to validate a new sender, audit DNS before launch, troubleshoot deliverability, or confirm a record change after propagation. It turns raw SPF syntax into a readable report so you can catch duplicate records, lookup limit issues, unsafe all mechanisms, and missing DMARC protection before they break authentication.
SPF record
example.com
TXTv=spf1 include:_spf.google.com ~all
Live SPF DNS lookup
Check the exact SPF TXT record receivers evaluate for your domain.
DNS lookups
7 / 10
Void lookups1 / 2
Lookup limit checks
See DNS and void lookup counts before receivers hit SPF permanent errors.
include:_spf.google.com
ip4:192.0.2.24
mx
Sender authorization
Confirm the record authorizes IPs, includes, redirects, or other valid senders.
+all~all-all
Safer all mechanism
Flag +all, neutral endings, and weak endings that leave unauthorized mail exposed.
No loops
No duplicates
No empty includes
Include hygiene
Find duplicate, empty, and looping includes that waste lookups or break evaluation.
DMARC
p=quarantine
SPF failures protected
DMARC compatibility
Check DMARC is published and enforcing so SPF failures can be acted on.

SPF checker FAQs

Answers to common questions about validating an SPF record, reading the results, and deciding what to fix next.
No. It performs a live DNS lookup and reports what is currently published.
It checks whether DNS returns a TXT record that starts with v=spf1 at your domain. That record tells receivers which servers are allowed to send mail for the domain.
SPF allows one SPF record per domain. If multiple SPF TXT records exist, receivers return a permanent error and SPF evaluation fails.
A valid SPF record starts with v=spf1, uses supported mechanisms and modifiers, separates each part with spaces, and contains valid domains, IP addresses, and CIDR ranges.
SPF allows at most 10 DNS lookups during evaluation. Include, a, mx, ptr, exists, and redirect mechanisms count toward the limit, including nested includes. Exceeding the limit causes a permanent error.
A void lookup is a DNS lookup that returns no useful answer. SPF allows only 2 void lookups because broken or missing include domains can slow evaluation and cause authentication errors.
An include loop happens when SPF records reference each other in a cycle. Receivers keep following includes until the lookup limit is reached, then SPF fails with a permanent error.
Long SPF records are more likely to hit DNS response limits or require TCP retries. Keeping the record under 450 bytes improves compatibility across receivers.
~all and -all tell receivers that unlisted senders are not authorized. Without a clear all mechanism, receivers may not know how strongly to treat unauthorized mail.
+all authorizes every server on the internet to send mail for your domain. That effectively disables SPF protection and makes spoofing easier.
The ptr mechanism is deprecated, slow, and unreliable because it depends on reverse DNS. Use explicit IP addresses or provider include mechanisms instead.
Duplicate include mechanisms waste DNS lookups. Each duplicate still counts toward the 10 lookup limit, even if it points to the same provider.
An empty include points to a domain that has no SPF record. That can happen because of a typo, a changed provider domain, or broken DNS, and it can cause SPF to fail.
SPF macros are valid but harder to audit and less consistently supported. Replacing macros with explicit IP addresses or include mechanisms usually makes records easier to debug.
A sending domain needs at least one authorized source, such as an include, IP address, a, mx, exists, or redirect. A record with no authorized source may be intentional for domains that never send email.
SPF only identifies authorized sending servers. DMARC tells receivers what to do when authentication fails, so a domain should publish DMARC and move toward quarantine or reject.
The standalone SPF checker validates DNS records. To see whether a real message passed SPF and whether SPF aligned with the From domain, use the email tester.

Here's why customers love Suped for DMARC monitoring

MONEYME cover

How MONEYME proactively strengthens domain security and unlocks higher email engagement with Suped

See how MONEYME uses Suped
Jam Cyber cover

How cybersecurity specialist Jam Cyber delivers scalable DMARC protection with Suped

See how Jam Cyber uses Suped
Vision Australia cover

How Vision Australia maintains full DMARC enforcement across a large domain portfolio with Suped

See how Vision Australia uses Suped
The POP Team cover

How The POP Team turns domain checks and DMARC visibility into client ready delivery work

See how The POP Team uses Suped
DigiBean cover

How DigiBean simplified DMARC monitoring and improved email security for their MSP clients

See how DigiBean uses Suped
Alliance Group cover

How Alliance Group moved from reactive guesswork to proactive email management with Suped

See how Alliance Group uses Suped
G2 LeaderG2 Users Most Likely To RecommendG2 Easiest To Do Business WithG2 High PerformerG2 Best Estimated ROI
DMARC monitoring

Start monitoring your DMARC reports today

Suped DMARC platform dashboard
What you'll get with Suped
Real-time DMARC report monitoring and analysis
Automated alerts for authentication failures
Clear recommendations to improve email deliverability
Protection against phishing and domain spoofing