XiaTools
Email tool

SPF Checker

Check the SPF record of a domain, count DNS lookups and spot common mistakes that hurt email delivery.

The SPF Checker is a free online diagnostic utility that inspects your domain's Sender Policy Framework records to ensure legitimate email delivery. It queries your DNS settings, parses the security policies, and validates your configuration against strict internet standards.

What is it

An SPF (Sender Policy Framework) record is a type of TXT record published in your domain's DNS zone that lists all authorized mail servers permitted to send email on behalf of your domain. The SPF Checker is a specialized diagnostic utility designed to read, parse, and evaluate these specific text records. When receiving mail servers get an email from your domain, they look up your SPF record to verify whether the sending server has your authorization. If the sending server's IP address is not listed in your SPF record, the email may be marked as spam or rejected entirely.

This tool automates the verification process by querying your authoritative name servers, retrieving the active TXT records, and analyzing their syntax and structure. Beyond simply confirming that a record exists, the checker evaluates complex nested mechanisms, modifier parameters, and the total count of DNS lookups your policy triggers. Because SPF records must adhere to strict formatting and size limitations to function properly, this utility acts as an automated auditor to catch invisible mistakes before they impact your email delivery rates.

Why it matters

Configuring a correct SPF record is a foundational requirement for modern email authentication, alongside DKIM and DMARC. Without a valid SPF policy, receiving mail servers cannot cryptographically or programmatically verify that an incoming message genuinely originates from your organization. This leaves your domain vulnerable to spoofing, where malicious actors can easily forge your sender address to launch phishing campaigns against your customers, partners, or employees.

Furthermore, mailbox providers like Google, Microsoft, and Yahoo enforce strict email authentication requirements for bulk senders. If your SPF record contains syntax errors, references non-existent domains, or exceeds the maximum lookup limit, receiving servers will treat your messages with suspicion. Exceeding the ten-lookup limit causes a permanent evaluation failure, resulting in an immediate drop in inbox placement. By routinely auditing your records with this tool, you protect your brand reputation, prevent business-critical emails from landing in spam folders, and maintain high deliverability.

How to use this tool

  1. Navigate to the XiaTools SPF Checker page in your web browser.
  2. Locate the input field designated for domain names.
  3. Type your fully qualified domain name into the box, ensuring you omit the http:// prefix and the @ symbol.
  4. Press the Check button to initiate the DNS query and analysis process.
  5. Review the generated breakdown of your SPF record, lookup count, and any flagged warnings.

How to read the results

When you run a check for a domain such as example.com, the tool provides a detailed breakdown of your email authentication posture. Here is how to interpret the typical outputs:

Common problems and how to fix them

Multiple SPF Records

Publishing more than one SPF TXT record for a single domain violates the official protocol specification. When receiving servers encounter multiple records, they cannot determine which policy to follow, resulting in an immediate SPF check failure.

To fix this issue, access your DNS management console, locate all TXT records starting with v=spf1, and consolidate them into a single record. Combine the authorized mechanisms into one line:

v=spf1 ip4:192.0.2.1 include:_spf.google.com ~all

Exceeding the 10-Lookup Limit

Nested includes and third-party email service providers often chain multiple SPF records together, quickly pushing your total DNS lookups past the maximum limit of ten.

To resolve lookup limit errors, flatten your SPF record by replacing resource-heavy include statements with explicit ip4 and ip6 blocks containing the exact IP ranges of your sending providers, or utilize an automated SPF flattening service.

v=spf1 ip4:192.0.2.1 ip4:198.51.100.5 ~all

Syntax and Typo Errors

A simple typographical error in a mechanism name, such as writing incude instead of include, renders that rule invalid or ignored by receiving mail servers.

Carefully review your raw record against standard syntax rules. Ensure that every mechanism is separated by a single space and that all IP addresses and domains are correctly formatted.

v=spf1 include:_spf.example.com -all

Best practices

Keep your SPF record as concise as possible by only including active email services that currently send messages on your behalf. Remove outdated third-party vendors or former marketing platforms immediately to prevent lingering security gaps. Always conclude your SPF record with a safe mechanism qualifier like ~all (softfail) rather than ?all (neutral), especially when setting up new domains, to monitor deliverability before enforcing stricter policies. Finally, make it a habit to check your record whenever you change your email hosting provider or add new transactional email tools.

Frequently asked questions

What is an SPF record?

An SPF record is a TXT entry in your DNS settings that specifies which mail servers and IP addresses are authorized to send emails on behalf of your domain.

Why is the 10-lookup limit important?

The SPF specification restricts each evaluation to a maximum of 10 DNS lookups to prevent denial-of-service attacks. Exceeding this limit causes a permanent error and fails email authentication.

Can I have multiple SPF records on one domain?

No, having multiple SPF records invalidates your configuration. Mail servers will reject or ignore multiple records, leading to email delivery failures.

What is the difference between ~all and -all?

The ~all modifier specifies a softfail, meaning unauthorized emails are accepted but flagged. The -all modifier specifies a hardfail, instructing receiving servers to reject unauthorized emails outright.

How often should I check my SPF record?

You should check your SPF record whenever you update your email service providers, add new marketing tools, or at least quarterly as part of your routine domain maintenance.

Does this tool check DKIM and DMARC as well?

No, this specific tool focuses exclusively on evaluating SPF records. You will need separate utilities to check your DKIM signatures and DMARC policies.

SPF Checker guides

Related tools