Free Tool · Runs in your browser

SPF Record Checker

Type a domain to fetch its SPF record live from DNS. We parse every mechanism, walk the include chain to count lookups against the 10-lookup limit, and flag the mistakes that silently break authentication.

  • 100% free
  • No signup
  • Nothing leaves your browser

SPF Record Checker

We fetch the TXT record live and follow every include to count DNS lookups.

Results appear here

Enter a domain to see its SPF record, every mechanism explained, the lookup count and what to fix.

How It Works

Three steps, no account needed

  1. 1

    Enter a domain

    Type the domain you send from, with or without https:// or www. We normalise it before querying.

  2. 2

    We fetch and walk the record

    Your browser pulls the TXT record over DNS-over-HTTPS, parses every term and follows each include to count lookups.

  3. 3

    Fix what is flagged

    Each check explains the problem in plain English. Failing records link straight to the SPF generator for a clean rebuild.

Domain & DNS Checkers

What an SPF record actually does

SPF (Sender Policy Framework) is a TXT record at your domain root that lists the servers allowed to send mail using your domain in the envelope sender. When Gmail or Microsoft receives a message, it looks up the record, compares the connecting IP against every mechanism in order and stops at the first match.

The result is pass, fail, softfail or neutral. On its own SPF rarely blocks mail, but DMARC needs either SPF or DKIM to pass and align with the From domain. For cold email, a broken SPF record means DMARC falls back to DKIM alone, and if that is misconfigured too, your campaigns land in spam.

v=spf1 include:_spf.google.com ~all

The 10 DNS lookup limit and how records break it

RFC 7208 caps the number of DNS-querying terms at 10 for the whole record, including every nested include. Terms that count: include, a, mx, ptr, exists and redirect. Terms that do not: ip4, ip6 and all. Exceed the limit and receivers return permerror, which most treat as a hard fail.

The trap is that includes hide their own lookups. A single include for a large provider can consume four or five on its own. Agencies that bolt on a CRM, a helpdesk, a marketing platform and two sending tools frequently hit 12 or 13 without realising it.

  • Remove includes for tools that no longer send from this domain.
  • Use a separate subdomain for marketing or transactional mail so each SPF record stays small.
  • Replace a static provider include with its ip4 ranges only if you are prepared to maintain them.
  • Never publish two v=spf1 records; merge them into one.

Choosing between ~all and -all for cold email

The final all term sets the policy for any server not listed. -all is a hard fail and ~all is a soft fail. Both are acceptable to Gmail and Microsoft, and both let DMARC do its job. What matters far more is that every legitimate sender is listed before the all term, and that you avoid +all and ?all entirely.

For outreach domains sending through Google Workspace or Microsoft 365, ~all is the safe default while you are still adding tools. Move to -all once the sender list is stable. InboxOne publishes a correct SPF record with the right include automatically when it provisions a mailbox, so new domains start clean.

Common SPF mistakes this checker catches

Most SPF failures are not exotic. They come from copy-paste errors, leftover includes and records that were never updated after switching providers. The checker flags each of these with a specific fix.

  • Multiple v=spf1 records, which cause an immediate permerror.
  • Terms placed after all, which are silently ignored.
  • Deprecated ptr mechanisms that some receivers skip entirely.
  • Void lookups where an include points at a domain with no SPF record.
  • TXT strings over 255 characters or total records that risk truncation.
  • Unknown tokens caused by typos like includes: or ip4= instead of ip4:.
FAQ

Frequently asked questions

Still stuck? Book a 30-minute deliverability call and we'll look at your setup together.

Enter your domain above. The checker fetches the TXT record live, confirms there is exactly one v=spf1 record, parses each mechanism, counts DNS lookups across every include and verifies the record ends with a proper all term. Anything wrong is listed with the exact change to make.

SPF allows at most 10 DNS-querying terms across the whole record, including nested includes. When a record exceeds that, receiving servers return permerror and usually treat the message as failing authentication. Remove unused includes or move some senders to a subdomain to get back under the limit.

Either works with Gmail and Microsoft as long as every real sender is listed. ~all (softfail) is forgiving while you add tools; -all (hard fail) is stricter once the setup is stable. Avoid +all, which authorises everyone, and ?all, which gives receivers no signal at all.

No. Publishing more than one TXT record starting with v=spf1 is a permanent error and SPF fails for every message. If two services each gave you a record, merge their include terms into a single record and delete the rest.

SPF is only one signal. Receivers also check DKIM, DMARC alignment, blacklists, domain age and engagement. Run the DKIM and DMARC checkers next, then the full deliverability check, which scores all of them together and points to the weakest link.

Yes, it is free with no signup and no limit. The lookup runs entirely in your browser against public DNS-over-HTTPS resolvers from Cloudflare and Google. InboxOne never receives the domains you check.

Ready to Scale Your Outbound?

Your Cold Email Infrastructure Shouldn't Be the Bottleneck.

Domains, mailboxes, DNS, deliverability, and platform exports — all from one dashboard. Starting at $39/month for 10 production-ready mailboxes.

Inbox One Logo

Cold email infrastructure platform. Buy domains, provision Google Workspace mailboxes, auto-configure DNS, and export to 5 outreach platforms — all from one dashboard.

© 2026 InboxOne. All rights reserved.