SPF Record Checker

Validate your Sender Policy Framework (SPF) record to ensure email deliverability and prevent spoofing.

Secure Your Domain Identity

SPF is just the first layer. ObserveOne provides full observability into your website's uptime and API health.

Monitor Uptime Free
No credit card required

Side-by-side breakdowns, no fluff.

What is SPF?

SPF (Sender Policy Framework) is an email authentication method that specifies which mail servers are authorized to send email on behalf of your domain.

Prevent Spoofing

SPF stops attackers from sending fake emails that appear to come from your organization.

Improve Deliverability

Google and Yahoo now require SPF/DKIM/DMARC for all bulk senders to reach the inbox.

How SPF Works

SPF is published as a single DNS TXT record listing which servers may send mail for your domain. When a receiving server gets a message, it reads that record and checks whether the sending IP is authorized. A pass supports your DMARC alignment; a fail tells the receiver the message may be spoofed.

Common SPF Misconfigurations

Too Many DNS Lookups

SPF allows a maximum of 10 DNS lookups. Exceeding that limit produces a PermError, and receivers ignore the record entirely.

More Than One Record

Publishing two or more SPF records on the same domain is invalid, and mail providers may fail the check outright. Merge every sender into one record.

Ending in +all

Ending a record in +all authorizes anyone to send as your domain. Use ~all (softfail) or -all (hardfail) instead.

Missing an include

Forgetting an include: for a provider you actually send through, such as a marketing platform, silently drops that mail. Avoid the deprecated ptr mechanism too.

SPF PermError: The 10-Lookup Limit (and the Void-Lookup Trap)

A PermError is not a fail. It means a receiving server refused to evaluate your record at all, and it is usually what sits behind "mail rejected despite a valid-looking SPF record." RFC 7208 (section 4.6.4) puts a hard limit on how many terms in a record may trigger a DNS lookup: the include, a, mx, ptr, and exists mechanisms, plus the redirect modifier. Cross 10 of those across the whole chain, nested includes included, and the record becomes a PermError. all, ip4, and ip6 never count, since none of them needs a lookup to evaluate.

Two things trip people up when they count by hand. First, a single mx mechanism can burn one lookup per MX record the domain publishes, not one lookup total. Second, a nested include brings its own lookups with it, so a single marketing platform can already use three or four of your ten before you have added anything of your own.

There is a second, separate way to hit PermError while staying under 10: RFC 7208 also caps "void lookups," DNS answers that come back empty or NXDOMAIN, at two. A third void lookup fails the record on its own, regardless of the total count, which is why a typo'd include: or a sender you dropped months ago can break deliverability on a record that otherwise looks well within the limit. This checker validates the syntax of your record's top-level line, but it does not resolve every include: target recursively or count the lookups inside it. To find out where you actually stand, count every include, a, mx, ptr, exists, and redirect term across the full chain by hand, or flatten the chain by replacing includes with the specific ip4/ip6 ranges they resolve to.

Frequently Asked Questions

What is the difference between ~all and -all?

~all is a softfail: receivers accept the mail but flag it as suspicious. -all is a hardfail: receivers reject or bin mail from servers not listed. -all is stricter, while ~all is the common starting point until you confirm every legitimate sender is covered.

Why does mail still fail with a valid SPF record?

A record can parse cleanly yet still fail in practice. The two usual causes are exceeding the 10 DNS-lookup limit, which triggers a PermError so the record is ignored, and a missing include for a provider you actually send through.

How many DNS lookups does SPF allow?

Ten. Each include, a, mx, ptr, and exists mechanism counts toward the limit; going over produces a PermError and receivers treat the record as unusable.

Can a domain have two SPF records?

No. A domain must publish exactly one SPF TXT record. Two or more make the result invalid, and many providers will fail the check outright. Merge every sender into a single record.

What is an SPF PermError?

A PermError means a receiving server could not evaluate your record at all and treats it as broken, not merely failing a check. RFC 7208 defines two causes: exceeding the 10-lookup limit across include, a, mx, ptr, exists, and redirect terms, or hitting more than two void lookups, DNS answers that come back empty or NXDOMAIN. Either one gets your mail treated as unauthenticated.

What counts toward the SPF lookup limit?

The include, a, mx, ptr, and exists mechanisms, plus the redirect modifier, each cause a DNS lookup and count toward the limit of 10 for the whole chain, nested includes included. All, ip4, and ip6 never count, since none of them requires a lookup to evaluate.