Sign up free

Check Your SPF Record and DNS Lookup Count

Check a domain's SPF record, see every include it pulls in, and test whether a server may send as you.

About SPF Record Checker

Run an SPF record check when mail starts landing in spam after you add a newsletter or CRM service, when bounces mention an SPF failure, or when DMARC reports show a permerror. Enter a domain and click Check. The tool finds the v=spf1 record, follows every include and redirect into a tree, and counts the terms that cost a DNS lookup. Receivers stop after 10 lookups, or after more than 2 that come back empty, and SPF then fails, so a record can look fine and still break.

It also flags more than one SPF record, a risky ending (+all lets anyone send, ?all protects nothing, while ~all and -all are fine), terms after all that are never read, a missing all, the deprecated ptr, includes without an SPF record, loops, unknown terms and records over 450 characters. Add an IP address to evaluate the record for that sender, and you get pass, fail, softfail or neutral plus the term that decided it. To write a new record, use the SPF Record Generator.

How to use SPF Record Checker

  1. 1
    Enter your domain

    Type the domain from your From address, or paste the address itself.

  2. 2
    Add an IP to test

    Optionally enter the sending server's IPv4 or IPv6 address to see whether SPF allows it.

  3. 3
    Run the SPF record checker

    Click Check to see the record, the include tree and the number of DNS lookups.

  4. 4
    Fix what's flagged

    Each warning or error comes with a plain fix, such as removing includes you no longer use.

Why use Cubfile for this

  • Include tree

    Every include and redirect expanded, with the record found at each level.

  • Lookup counter

    DNS-lookup terms counted against the limit of 10, and empty answers against 2.

  • IP test

    Evaluates ip4, ip6, a, mx, include, all and redirect, and names the deciding term.

  • Plain fixes

    Multiple records, +all, a missing all, ptr, loops and unknown terms, each explained.

FAQ

SPF Record Checker: questions and answers

What does "too many DNS lookups" mean in an SPF check?
The include, a, mx, ptr, exists and redirect terms each cost a DNS lookup, and so do the ones inside nested includes. Above 10, receivers return a permanent error and SPF fails for all your mail, so remove services you no longer use or list your own servers as ip4 and ip6 ranges.
Should my SPF record end in ~all or -all?
Both protect you. With ~all (soft fail) receivers treat unlisted senders as suspicious, and with -all (fail) they may reject them, but never use +all, which lets anyone send as you.
Can a domain have two SPF records?
No. Two v=spf1 records make receivers return a permanent error. Merge them into one, which the SPF Record Generator can build for you.
How does the IP test decide?
It reads the record in order, as a receiving server would, and the first term that matches the IP sets the result. Includes that use macros (%) need a real message to expand, so they're skipped.
Is the SPF record checker free?
Yes, with no sign-up, and it doesn't use your daily tasks. An hourly allowance applies, higher for signed-in members, and results aren't stored.
Share SPF Record Checker with a friendIt runs in any browser, and they can try it without signing up.

Related tools

MAIL MX Record LookupSee which mail servers receive email for a domain, in priority order.
MAIL DMARC CheckerRead a domain’s DMARC policy and where its reports go.
MAIL Email Header AnalyzerPaste email headers to see the servers a message passed, delays and SPF/DKIM results.
MAIL Email Address CheckerCheck email addresses for typos, disposable domains and working mail servers.
MAIL DKIM CheckerFind and check a domain’s DKIM keys, trying common selectors for you.
MAIL DMARC Record GeneratorCreate a DMARC record step by step, from monitoring to reject.
MAIL SPF Record GeneratorBuild a correct SPF record for your mail providers.
SEO Broken Link CheckerCheck every link on a page and list the ones that are broken or redirected.