Security Tools
SPF Checker
Look up a domain's SPF record and see exactly what each mechanism does, in the order mail servers evaluate it.
How it works
The tool fetches the domain's TXT records live over DNS and finds the one that starts with v=spf1. Then it reads every mechanism in it and flags the mistakes that actually break SPF in practice, like having more than one SPF record or no catch-all mechanism.
FAQ
- What is SPF?
- SPF stands for Sender Policy Framework. It's a DNS TXT record that lists which mail servers are allowed to send email for a domain. Receiving mail servers check this record to help decide whether an incoming message from that domain is legitimate.
- What do Pass, Fail, SoftFail, and Neutral mean?
- These are qualifiers you can add to each mechanism. They control what happens when that mechanism matches an incoming message. Pass is the default when no symbol is given, and it authorizes the sender outright. Fail tells receivers to reject anything that matches. SoftFail (~) asks receivers to accept the message but flag it as suspicious. Neutral (?) gives no stated opinion either way.
- Why does having no "all" mechanism matter?
- Without an "all" mechanism, anything not matched by an earlier mechanism has no defined outcome in SPF evaluation. Most mail providers treat that case cautiously instead of a clear pass or fail. This can lead to inconsistent handling of legitimate mail.
- Why does the number of lookups matter?
- RFC 7208 caps SPF evaluation at 10 DNS lookups total. This count includes every include, a, mx, ptr, and exists mechanism, plus anything they reference in turn. Go over that limit and SPF evaluation hard-fails, no matter how well-intentioned the record is.