What an SPF record actually does
SPF (Sender Policy Framework) is a TXT record at your domain root that lists the servers allowed to send mail using your domain in the envelope sender. When Gmail or Microsoft receives a message, it looks up the record, compares the connecting IP against every mechanism in order and stops at the first match.
The result is pass, fail, softfail or neutral. On its own SPF rarely blocks mail, but DMARC needs either SPF or DKIM to pass and align with the From domain. For cold email, a broken SPF record means DMARC falls back to DKIM alone, and if that is misconfigured too, your campaigns land in spam.
v=spf1 include:_spf.google.com ~allThe 10 DNS lookup limit and how records break it
RFC 7208 caps the number of DNS-querying terms at 10 for the whole record, including every nested include. Terms that count: include, a, mx, ptr, exists and redirect. Terms that do not: ip4, ip6 and all. Exceed the limit and receivers return permerror, which most treat as a hard fail.
The trap is that includes hide their own lookups. A single include for a large provider can consume four or five on its own. Agencies that bolt on a CRM, a helpdesk, a marketing platform and two sending tools frequently hit 12 or 13 without realising it.
- Remove includes for tools that no longer send from this domain.
- Use a separate subdomain for marketing or transactional mail so each SPF record stays small.
- Replace a static provider include with its ip4 ranges only if you are prepared to maintain them.
- Never publish two v=spf1 records; merge them into one.
Choosing between ~all and -all for cold email
The final all term sets the policy for any server not listed. -all is a hard fail and ~all is a soft fail. Both are acceptable to Gmail and Microsoft, and both let DMARC do its job. What matters far more is that every legitimate sender is listed before the all term, and that you avoid +all and ?all entirely.
For outreach domains sending through Google Workspace or Microsoft 365, ~all is the safe default while you are still adding tools. Move to -all once the sender list is stable. InboxOne publishes a correct SPF record with the right include automatically when it provisions a mailbox, so new domains start clean.
Common SPF mistakes this checker catches
Most SPF failures are not exotic. They come from copy-paste errors, leftover includes and records that were never updated after switching providers. The checker flags each of these with a specific fix.
- Multiple v=spf1 records, which cause an immediate permerror.
- Terms placed after all, which are silently ignored.
- Deprecated ptr mechanisms that some receivers skip entirely.
- Void lookups where an include points at a domain with no SPF record.
- TXT strings over 255 characters or total records that risk truncation.
- Unknown tokens caused by typos like includes: or ip4= instead of ip4:.

