Look up a domain's SPF record, follow every include, and count the DNS lookups receivers will spend evaluating it. Each mechanism is explained in plain language. Free, no sign-up, runs in your browser.
SPF (Sender Policy Framework, RFC 7208) is a TXT record listing the servers allowed to send mail for a domain. A receiver checks the connecting IP against the record published on the envelope sender's domain (the Return-Path), not the From address people see. That is why SPF alone cannot stop spoofing, and why DMARC exists.
Most broken SPF records fail in one of three ways: two records instead of one, more than ten DNS lookups once includes are expanded, or an include: that points at a domain with no SPF record. All three produce a permanent error, and SPF fails for every message, not only some.
v=spf1Must start the record. A domain may publish exactly one; two SPF records are a permanent error.
include:Pulls in another domain's list, usually your email platform's. Costs a DNS lookup, plus every lookup inside it.
ip4: / ip6:Authorize addresses or ranges directly. Free: no DNS lookup.
a / mxAuthorize the domain's own A or MX hosts. One lookup each.
include, a, mx, ptr, exists and redirect each cost one lookup, nested includes included. Past 10, SPF fails.
~all vs -all~all soft-fails unlisted senders, -all fails them. With DMARC enforced, either works; +all and ?all protect nothing.
Remove includes for services you no longer use, replace a and mx with the ip4 ranges they resolve to if those are stable, and move bulk-sending platforms onto their own subdomain (for example news.example.com) with its own SPF record. Avoid automatic "flattening" services unless they track your providers' changes.
Either is fine once DMARC is enforced, because DMARC decides what happens to failing mail. ~all is the safer default: forwarded mail fails SPF, and some receivers reject outright on -all before DMARC is even considered.
SPF is not inherited. Each hostname that appears as an envelope sender needs its own record. A subdomain that never sends mail can publish v=spf1 -all so nobody can use it.
SPF passed for the Return-Path domain, but that domain belongs to your sending platform, not to your From domain, so it does not align. Set up a custom return path (a bounce domain on your own domain) or rely on DKIM alignment.
Point an MCP client (Claude, Cursor, any agent) at https://powerline.ai/mcp and call check_record, or hit the JSON endpoint directly. No key, no account.
curl "https://powerline.ai/api/tools/spf?domain=example.com"
Read the DMARC policy, alignment and reporting tags, and check that report addresses will accept reports.
Find the DKIM public key for a selector (or auto-detect common ones) and check its size and flags.
SPF, DKIM, DMARC, MX, MTA-STS, TLS-RPT, BIMI and blacklists in one run, scored out of 100 with a fix list.
Trace a message hop by hop, read the receiver's SPF/DKIM/DMARC verdicts and check DMARC alignment.
See how your HTML email actually renders in real Gmail, Outlook.com and Yahoo Mail accounts. Free screenshots.