Free tool
SPF checker: lookup tree, 10-lookup count and the fixed record
Enter a domain to check its SPF record.
Every include is followed to the end and counted. Lookups go from your browser to Cloudflare's public DNS resolver; nothing is stored.
- Every include followed, with its own lookup count
- Lookups against the limit of 10, void lookups against 2
- Each mechanism and the all ending in plain words
- The corrected record, ready to paste into your DNS
About this tool
About the SPF checker
A valid record is one TXT record that starts with v=spf1, needs at most 10 DNS lookups including every nested include, has at most 2 void lookups and ends in ~all or -all. Anything else makes receivers return permerror or let any server pass.
The checker follows every include to the end and shows the tree with the lookups each branch costs, explains each mechanism in plain words and writes the record to publish instead. The lookups run in your browser; nothing is stored.
How it works
How to read the SPF result
The verdict on top answers one question: can receivers evaluate the record for every message? The tree under it shows why. Each include carries the number of lookups it costs with everything inside it, so the branch that takes the record over 10 is the one with the biggest number.
- Permerror: two SPF records, more than 10 lookups, more than 2 void lookups, an include whose domain has no SPF record, or a term that is not SPF syntax (include= instead of include:, a trailing dot); SPF then fails for every message, and DMARC counts it as a fail
- Lookups: include, a, mx, ptr, exists and redirect cost one each, plus everything inside an include; ip4, ip6 and all cost none, which is why replacing an include with its addresses (flattening) lowers the count
- Void lookups: a name in the record that returns no answer, such as an include of a service you left or a: pointing to a deleted host; RFC 7208 allows two
- -all, ~all, ?all, +all: what happens to a server the record does not list; -all fails it, ~all soft fails it (accepted and usually filtered), ?all says nothing and +all passes every server on the internet
- 8 or 9 of 10 lookups (warning): the record works today; one more service, or a provider adding a nested include, breaks it
- Repeated terms, ptr and terms after all (warnings): delete them; receivers stop reading at all
Background
How the fixed record is written
- Two or more records are merged into one, keeping every mechanism once
- Includes of domains with no SPF record, repeated terms, ptr and syntax errors are removed
- +all, ?all or a missing all becomes ~all; an existing -all stays
- No SPF record at all: the record allows the provider your MX records point to (Google Workspace: include:_spf.google.com, Microsoft 365: include:spf.protection.outlook.com, both from the providers' documentation)
- Still over 10 lookups: a flattened record replaces the heaviest includes with the addresses they list today; Microsoft 365's include is left alone because Microsoft says its addresses change often
- Before you flatten, remove services you no longer send from, or move one service to a subdomain with its own SPF record and its own 10 lookups
- The step-by-step fixes are in fixing SPF permerror; Google Workspace values are in Google Workspace SPF, DKIM and DMARC
Background
SPF on cold email domains
A cold email domain usually sends through one mailbox provider, so its SPF record is one include and ~all or -all, far from the limit. Lookups pile up on the main company domain, where marketing, billing, support and CRM tools each add an include. That is one more reason to keep cold email on separate domains.
SPF is one of three records. Check the DKIM key and the DMARC policy of the same domain, or all of them with MX at once in the SPF, DKIM and DMARC checker. Gmail and Yahoo require all three from bulk senders: what cold email domains need.
Free guide19 min read
Send 100,000 cold emails a month
Domains and mailboxes you need, DNS, warm-up, lists, copy and follow-ups, with a launch checklist, sent to your inbox.
Questions
How do I check my SPF record?
Enter the domain above. The checker reads the TXT record that starts with v=spf1, follows every include, counts the DNS lookups and lists what to fix. By hand: dig TXT example.com or nslookup -type=txt example.com.
What does SPF permerror mean?
Permerror is a permanent error: the receiver could not evaluate the record, so SPF fails for every message. The usual causes are more than 10 DNS lookups, two SPF records on one domain, an include whose domain has no SPF record, more than 2 void lookups, or a syntax error such as include= instead of include:.
How do I fix too many DNS lookups in SPF?
Remove includes of services you no longer send from, move one sending service to a subdomain with its own SPF record, or replace a stable provider's include with its ip4 and ip6 ranges (flattening). The checker shows which include costs the most and writes a flattened record when cleanup is not enough.
Should SPF end in ~all or -all?
Both are valid. -all asks receivers to reject unlisted servers; ~all asks them to accept and mark the mail. With DMARC in place, both count as an SPF fail. Microsoft recommends -all for Microsoft 365 domains; Google's documented record ends in ~all.
Can a domain have two SPF records?
No. RFC 7208 allows one; with two, every receiver returns permerror. Merge them into one record that starts with v=spf1 and lists every service once.
What is an SPF void lookup?
A DNS lookup in the record that returns no answer or a name that does not exist, for example an include of a service you closed. More than two make the record fail with permerror.
Is SPF flattening safe?
Only for providers with stable, documented addresses, and only if you recheck the record regularly: when the provider adds an address, mail from it fails SPF until you update the record. Microsoft advises against flattening its include.
Does this tool store the domains I check?
No. The page queries Cloudflare's public DNS resolver from your browser. We receive nothing unless you ask us to email you the fixes.
In your AI assistant
Run the same checks in Claude or ChatGPT
Free SKILL.md files with the rules behind this tool. Install them in Claude or Claude Code, or paste them into ChatGPT, Gemini, Grok or Cursor.
Mailboxes, warm-up and sending in one place
$2.50 a mailbox a month. DNS records are set for you, and every mailbox shows its warm-up numbers from day one.
Deliverability call
Talk to our deliverability team
Book a call with the people who run our mailbox infrastructure. We look at your current setup and tell you what to change. Running 1,000+ mailboxes? We also quote a volume price below every vendor list price in our comparisons, warm-up and sending included.
- Review your domains, DNS records and current inbox placement
- Size the setup: domains, mailboxes per domain and daily volume per mailbox
- Plan warm-up and the move from your current provider or sequencer
- 1,000+ mailboxes: a volume price per mailbox for your setup
Free call
See open times in your time zone and book on this page.
Or open the booking pageLoading available times…
Open the booking page instead