MailHealthKit

Email domain diagnostics

Free SPF Checker

Check your domain's SPF record, DNS lookup count and email authentication configuration.

No signup required. We look up public DNS records only.

  • SPF record
  • DNS lookup count
  • DMARC policy

Learn about SPF

What is an SPF record?

SPF (Sender Policy Framework, RFC 7208) is a DNS TXT record that lists the servers and services allowed to send email using your domain in the envelope sender address. Receiving mail systems look it up to check whether a message came from an authorized source.

An SPF record starts with v=spf1, followed by terms such as include:, ip4: and mx, and usually ends with an all mechanism that says how to treat everything else.

What does this SPF checker test?

  • Whether the domain publishes an SPF record, and whether it publishes more than one.
  • Whether the record's syntax is valid.
  • How many DNS lookups evaluating the record requires, following include and redirect into other records.
  • Broken or looping includes, and how the record treats unlisted senders.
  • The domain's DMARC record at _dmarc., for context.

It does not check DKIM, blocklists, sender reputation or inbox placement.

Common SPF configuration problems

  • More than one SPF record. A domain should publish a single record; with several, SPF evaluation returns a permanent error.
  • Too many DNS lookups. Adding services one include at a time can exceed the 10-lookup limit.
  • Syntax errors. A mistyped mechanism or IP address makes the whole record invalid.
  • Includes that no longer exist. An include pointing at a domain without an SPF record causes a permanent error when it is reached.
  • +all authorizes every server on the internet to send as the domain.

The SPF 10-DNS-lookup limit

To keep evaluation bounded, SPF allows at most 10 terms that cause DNS lookups: include, a, mx, ptr, exists and the redirect modifier. ip4, ip6 and all don't count.

Lookups inside included records count toward the same total, so a single include can use several. If evaluation needs more than 10, receivers return a permanent error and SPF fails. This checker follows includes and redirects and shows where each lookup comes from.

Lookup cost per term

include:
1 + nested
redirect=
1 + nested
a mx ptr exists
1 each
ip4: ip6: all
0

Limit: 10 per evaluation

SPF and DMARC

DMARC builds on SPF and DKIM. It lets a domain publish a policy (p=none, quarantine or reject) that tells receivers how to handle messages that fail authentication, and it can request reports about mail sent using the domain.

For DMARC, SPF only counts when the domain it checks matches the domain in the visible From address. That's why this checker shows your DMARC record alongside SPF.

FAQ

Is ~all or -all better?

Both are valid. -all asks receivers to treat mail from unlisted servers as failing SPF; ~all marks it as a soft failure, which receivers usually accept but may weigh as suspicious. Which one suits a domain depends on how confident you are that every legitimate sender is listed.

Does a passing result mean my email will be delivered?

No. This checker reports what is published in DNS. Delivery also depends on DKIM, sender reputation, message content and each receiving system's own filtering.

Does the checker send any email?

No. It only looks up public DNS records for the domain you enter.

Can I check a subdomain?

Yes. Enter the subdomain that appears in your email addresses. A leading www. is removed, because it is a website host rather than a mail domain.

Is DKIM checked?

Not yet. Checking DKIM requires the selector used by your sending service, which can't be reliably discovered from DNS.