SPF checker
Look up your SPF DNS records and analyze for errors.
Check your SPF record is valid and correct
Live DNS lookup
Run a live SPF DNS lookup to verify the record receivers use, catch syntax issues, and check whether your domain stays within SPF limits. For ongoing management, use Suped's hosted SPF and SPF flattening to keep records accurate and within lookup limits as providers change. For background, review the SPF lookup limit and SPF TXT formatting guide.
Get started
One SPF checker, endless uses
Use the SPF checker to validate a new sender, audit DNS before launch, troubleshoot deliverability, or confirm a record change after propagation. It turns raw SPF syntax into a readable report so you can catch duplicate records, lookup limit issues, unsafe all mechanisms, and missing DMARC protection before they break authentication.
SPF record
example.com
TXTv=spf1 include:_spf.google.com ~all
Live SPF DNS lookup
Check the exact SPF TXT record receivers evaluate for your domain.
DNS lookups
7 / 10
Void lookups1 / 2
Lookup limit checks
See DNS and void lookup counts before receivers hit SPF permanent errors.
include:_spf.google.com
ip4:192.0.2.24
mx
Sender authorization
Confirm the record authorizes IPs, includes, redirects, or other valid senders.
+all~all-all
Safer all mechanism
Flag +all, neutral endings, and weak endings that leave unauthorized mail exposed.
No loops
No duplicates
No empty includes
Include hygiene
Find duplicate, empty, and looping includes that waste lookups or break evaluation.
DMARC
p=quarantineSPF failures protected
DMARC compatibility
Check DMARC is published and enforcing so SPF failures can be acted on.
SPF checker FAQs
Answers to common questions about validating an SPF record, reading the results, and deciding what to fix next.
No. It performs a live DNS lookup and reports what is currently published.
It checks whether DNS returns a TXT record that starts with v=spf1 at your domain. That record tells receivers which servers are allowed to send mail for the domain.
SPF allows one SPF record per domain. If multiple SPF TXT records exist, receivers return a permanent error and SPF evaluation fails.
A valid SPF record starts with v=spf1, uses supported mechanisms and modifiers, separates each part with spaces, and contains valid domains, IP addresses, and CIDR ranges.
SPF allows at most 10 DNS lookups during evaluation. Include, a, mx, ptr, exists, and redirect mechanisms count toward the limit, including nested includes. Exceeding the limit causes a permanent error.
A void lookup is a DNS lookup that returns no useful answer. SPF allows only 2 void lookups because broken or missing include domains can slow evaluation and cause authentication errors.
An include loop happens when SPF records reference each other in a cycle. Receivers keep following includes until the lookup limit is reached, then SPF fails with a permanent error.
Long SPF records are more likely to hit DNS response limits or require TCP retries. Keeping the record under 450 bytes improves compatibility across receivers.
~all and -all tell receivers that unlisted senders are not authorized. Without a clear all mechanism, receivers may not know how strongly to treat unauthorized mail.
+all authorizes every server on the internet to send mail for your domain. That effectively disables SPF protection and makes spoofing easier.
The ptr mechanism is deprecated, slow, and unreliable because it depends on reverse DNS. Use explicit IP addresses or provider include mechanisms instead.
Duplicate include mechanisms waste DNS lookups. Each duplicate still counts toward the 10 lookup limit, even if it points to the same provider.
An empty include points to a domain that has no SPF record. That can happen because of a typo, a changed provider domain, or broken DNS, and it can cause SPF to fail.
SPF macros are valid but harder to audit and less consistently supported. Replacing macros with explicit IP addresses or include mechanisms usually makes records easier to debug.
A sending domain needs at least one authorized source, such as an include, IP address, a, mx, exists, or redirect. A record with no authorized source may be intentional for domains that never send email.
SPF only identifies authorized sending servers. DMARC tells receivers what to do when authentication fails, so a domain should publish DMARC and move toward quarantine or reject.
The standalone SPF checker validates DNS records. To see whether a real message passed SPF and whether SPF aligned with the From domain, use the email tester.

How MONEYME proactively strengthens domain security and unlocks higher email engagement with Suped
See how MONEYME uses Suped
How cybersecurity specialist Jam Cyber delivers scalable DMARC protection with Suped
See how Jam Cyber uses Suped

How Vision Australia maintains full DMARC enforcement across a large domain portfolio with Suped
See how Vision Australia uses Suped

How The POP Team turns domain checks and DMARC visibility into client ready delivery work
See how The POP Team uses Suped

How DigiBean simplified DMARC monitoring and improved email security for their MSP clients
See how DigiBean uses Suped

How Alliance Group moved from reactive guesswork to proactive email management with Suped
See how Alliance Group uses Suped
Start monitoring your DMARC reports today

What you'll get with Suped
Real-time DMARC report monitoring and analysis
Automated alerts for authentication failures
Clear recommendations to improve email deliverability
Protection against phishing and domain spoofing

