The SPF Checker is a free online diagnostic utility that inspects your domain's Sender Policy Framework records to ensure legitimate email delivery. It queries your DNS settings, parses the security policies, and validates your configuration against strict internet standards.
What is it
An SPF (Sender Policy Framework) record is a type of TXT record published in your domain's DNS zone that lists all authorized mail servers permitted to send email on behalf of your domain. The SPF Checker is a specialized diagnostic utility designed to read, parse, and evaluate these specific text records. When receiving mail servers get an email from your domain, they look up your SPF record to verify whether the sending server has your authorization. If the sending server's IP address is not listed in your SPF record, the email may be marked as spam or rejected entirely.
This tool automates the verification process by querying your authoritative name servers, retrieving the active TXT records, and analyzing their syntax and structure. Beyond simply confirming that a record exists, the checker evaluates complex nested mechanisms, modifier parameters, and the total count of DNS lookups your policy triggers. Because SPF records must adhere to strict formatting and size limitations to function properly, this utility acts as an automated auditor to catch invisible mistakes before they impact your email delivery rates.
Why it matters
Configuring a correct SPF record is a foundational requirement for modern email authentication, alongside DKIM and DMARC. Without a valid SPF policy, receiving mail servers cannot cryptographically or programmatically verify that an incoming message genuinely originates from your organization. This leaves your domain vulnerable to spoofing, where malicious actors can easily forge your sender address to launch phishing campaigns against your customers, partners, or employees.
Furthermore, mailbox providers like Google, Microsoft, and Yahoo enforce strict email authentication requirements for bulk senders. If your SPF record contains syntax errors, references non-existent domains, or exceeds the maximum lookup limit, receiving servers will treat your messages with suspicion. Exceeding the ten-lookup limit causes a permanent evaluation failure, resulting in an immediate drop in inbox placement. By routinely auditing your records with this tool, you protect your brand reputation, prevent business-critical emails from landing in spam folders, and maintain high deliverability.
How to use this tool
- Navigate to the XiaTools SPF Checker page in your web browser.
- Locate the input field designated for domain names.
- Type your fully qualified domain name into the box, ensuring you omit the http:// prefix and the @ symbol.
- Press the Check button to initiate the DNS query and analysis process.
- Review the generated breakdown of your SPF record, lookup count, and any flagged warnings.
How to read the results
When you run a check for a domain such as example.com, the tool provides a detailed breakdown of your email authentication posture. Here is how to interpret the typical outputs:
- Status: Indicates whether a valid SPF record was found. A successful result shows a green status, while missing or multiple records show a red error state.
- Raw Record: Displays the exact TXT string published in your DNS, such as
v=spf1 include:_spf.google.com ~all. This lets you visually inspect the syntax. - DNS Lookups: Counts every mechanism that requires an additional DNS query, such as
include,a,mx, andptr. For example, if your record usesv=spf1 include:spf.example.com include:mail.example.net ~all, the tool counts 2 lookups. The specification sets a hard limit of 10 lookups; exceeding this results in a PermError. - Mechanisms and Modifiers: Breaks down individual tags. An
ip4:192.0.2.1mechanism authorizes a specific IPv4 address without consuming a lookup. The~allmodifier at the end specifies a softfail policy for unlisted servers, whereas-allenforces a strict hardfail.
Common problems and how to fix them
Multiple SPF Records
Publishing more than one SPF TXT record for a single domain violates the official protocol specification. When receiving servers encounter multiple records, they cannot determine which policy to follow, resulting in an immediate SPF check failure.
To fix this issue, access your DNS management console, locate all TXT records starting with v=spf1, and consolidate them into a single record. Combine the authorized mechanisms into one line:
v=spf1 ip4:192.0.2.1 include:_spf.google.com ~all
Exceeding the 10-Lookup Limit
Nested includes and third-party email service providers often chain multiple SPF records together, quickly pushing your total DNS lookups past the maximum limit of ten.
To resolve lookup limit errors, flatten your SPF record by replacing resource-heavy include statements with explicit ip4 and ip6 blocks containing the exact IP ranges of your sending providers, or utilize an automated SPF flattening service.
v=spf1 ip4:192.0.2.1 ip4:198.51.100.5 ~all
Syntax and Typo Errors
A simple typographical error in a mechanism name, such as writing incude instead of include, renders that rule invalid or ignored by receiving mail servers.
Carefully review your raw record against standard syntax rules. Ensure that every mechanism is separated by a single space and that all IP addresses and domains are correctly formatted.
v=spf1 include:_spf.example.com -all
Best practices
Keep your SPF record as concise as possible by only including active email services that currently send messages on your behalf. Remove outdated third-party vendors or former marketing platforms immediately to prevent lingering security gaps. Always conclude your SPF record with a safe mechanism qualifier like ~all (softfail) rather than ?all (neutral), especially when setting up new domains, to monitor deliverability before enforcing stricter policies. Finally, make it a habit to check your record whenever you change your email hosting provider or add new transactional email tools.