Tools
SPF Checker — Check SPF Record Online
Check an SPF record online for syntax errors, duplicate records and DNS lookup risks.
What this report checks
SPF Checker reads every root TXT record that starts with v=spf1, validates the policy shape and explains risks that can make legitimate mail fail authentication.
| Signal | Healthy result | Problem detected | Recommended action |
|---|---|---|---|
| Record count | One SPF policy at the root | No policy or multiple v=spf1 records | Publish one policy and merge every authorised sender into it. |
| Final mechanism | A deliberate ~all or -all ending | Missing, duplicated or overly permissive all | Inventory senders first; use softfail while testing and hardfail only after validation. |
| DNS lookup risk | Fewer than 10 lookup-causing mechanisms | Nested include, a, mx, ptr, exists or redirect chains | Remove obsolete includes and consolidate providers without flattening records blindly. |
| Syntax | Recognised mechanisms and qualifiers | Typos, invalid CIDR values or text after all | Correct the TXT value, wait for its TTL and check again. |
From result to verified repair
- 1Enter the root domain, not an email address or URL.
- 2Compare each finding with the services that actually send mail.
- 3Update the single SPF TXT record at the authoritative DNS provider.
- 4Check again after caches expire, then confirm SPF and DMARC alignment in a real message header.
What this tool cannot prove
- It cannot discover private sending systems that are absent from DNS.
- Valid SPF does not guarantee DMARC alignment or inbox placement.
- Nested provider records can change the ten-lookup result over time.
Overview
Check an SPF record online for syntax errors, duplicate records and DNS lookup risks.
Authentication is the foundation
TXT proves control. MX directs incoming mail. SPF, DKIM and DMARC give receivers evidence that your messages are legitimate.
Related guides
Frequently asked questions
Yes. You only add the records shown for your domain.