Play Video

Oppora's Claude MCP is Live. Connect our Email Database & Outreach features with any tool to build smart automations inside Claude. Start for Free

SPF record checker

Enter a domain to read its SPF record, count DNS lookups and find problems before they hurt delivery.

Free, no signup. Up to 10 checks per hour.

How to read an SPF check

SPF (Sender Policy Framework) is a TXT record that lists the servers allowed to send email for your domain. Receivers compare the sending server against it.

One record, starting with v=spf1

A domain gets exactly one SPF record. Each term in it either names senders (ip4, ip6, include, a, mx) or sets the rule for everyone else (all).

When you add a new tool that sends as you, such as a CRM or help desk, add its include to the existing record. Publishing a second v=spf1 record breaks SPF for the whole domain.

The 10-lookup limit

RFC 7208 lets a receiver make at most 10 DNS lookups while checking SPF. Every include, a, mx, ptr, exists and redirect costs one, and so do the includes nested inside them.

Past 10, the result is a permanent error and SPF fails. The include tree above shows where the lookups come from, so you can see which service is the expensive one.

Fixing common problems

Remove includes for services you stopped using. Replace a and mx with the actual ip4 or ip6 ranges when those addresses rarely change.

End the record with ~all or -all. Avoid +all, which lets anyone pass, and ptr, which the standard says not to use. If one domain needs too many senders, move bulk or marketing mail to a subdomain with its own record.

Need more than one check?

Warm up new mailboxes and watch SPF, DKIM, DMARC and blacklists for every inbox you connect. See Email Warmup

Free plan, no credit card

SPF Checker FAQ

What is an SPF record?

An SPF record is a TXT record in DNS that lists the mail servers allowed to send email for a domain. Receiving servers check the sending IP against it, and DMARC uses the result.

What does "too many DNS lookups" mean?

Your record, counting every include nested inside it, needs more than the 10 DNS lookups RFC 7208 allows. Receivers stop and return a permanent error, which counts as an SPF failure. Removing unused includes usually fixes it.

Should I use ~all or -all?

Both are fine once the record lists every service that sends for you. ~all (soft fail) is the more common choice, and DMARC treats soft fail and fail the same way. Use -all if you want receivers that act on SPF alone to reject unlisted senders.

Can I have two SPF records?

No. A domain with more than one v=spf1 record returns a permanent error, so SPF fails everywhere. Merge the mechanisms into a single record.

What is a void lookup?

A DNS lookup in your SPF record that returns no records, for example an include for a domain that no longer exists. RFC 7208 suggests receivers allow only two, and more than that is a permanent error.

Is SPF enough to reach the inbox?

No. Gmail, Yahoo and Outlook.com expect bulk senders to pass SPF and DKIM and to publish a DMARC record. Check DKIM and DMARC as well, and keep spam complaints low.

Let’s Vibe Sales too!