About SPF Record Checker
Run an SPF record check when mail starts landing in spam after you add a newsletter or CRM service, when bounces mention an SPF failure, or when DMARC reports show a permerror. Enter a domain and click Check. The tool finds the v=spf1 record, follows every include and redirect into a tree, and counts the terms that cost a DNS lookup. Receivers stop after 10 lookups, or after more than 2 that come back empty, and SPF then fails, so a record can look fine and still break.
It also flags more than one SPF record, a risky ending (+all lets anyone send, ?all protects nothing, while ~all and -all are fine), terms after all that are never read, a missing all, the deprecated ptr, includes without an SPF record, loops, unknown terms and records over 450 characters. Add an IP address to evaluate the record for that sender, and you get pass, fail, softfail or neutral plus the term that decided it. To write a new record, use the SPF Record Generator.
How to use SPF Record Checker
- 1Enter your domain
Type the domain from your From address, or paste the address itself.
- 2Add an IP to test
Optionally enter the sending server's IPv4 or IPv6 address to see whether SPF allows it.
- 3Run the SPF record checker
Click Check to see the record, the include tree and the number of DNS lookups.
- 4Fix what's flagged
Each warning or error comes with a plain fix, such as removing includes you no longer use.
Why use Cubfile for this
- Include tree
Every include and redirect expanded, with the record found at each level.
- Lookup counter
DNS-lookup terms counted against the limit of 10, and empty answers against 2.
- IP test
Evaluates ip4, ip6, a, mx, include, all and redirect, and names the deciding term.
- Plain fixes
Multiple records, +all, a missing all, ptr, loops and unknown terms, each explained.