SPF record checker

Look up a domain's SPF record, follow every include, and count the DNS lookups receivers will spend evaluating it. Each mechanism is explained in plain language. Free, no sign-up, runs in your browser.

Enter the domain in your From address, or the one in your Return-Path if your platform sends with its own.

How it works

How SPF works, and where it breaks

SPF (Sender Policy Framework, RFC 7208) is a TXT record listing the servers allowed to send mail for a domain. A receiver checks the connecting IP against the record published on the envelope sender's domain (the Return-Path), not the From address people see. That is why SPF alone cannot stop spoofing, and why DMARC exists.

Most broken SPF records fail in one of three ways: two records instead of one, more than ten DNS lookups once includes are expanded, or an include: that points at a domain with no SPF record. All three produce a permanent error, and SPF fails for every message, not only some.

v=spf1

Must start the record. A domain may publish exactly one; two SPF records are a permanent error.

include:

Pulls in another domain's list, usually your email platform's. Costs a DNS lookup, plus every lookup inside it.

ip4: / ip6:

Authorize addresses or ranges directly. Free: no DNS lookup.

a / mx

Authorize the domain's own A or MX hosts. One lookup each.

The 10-lookup limit

include, a, mx, ptr, exists and redirect each cost one lookup, nested includes included. Past 10, SPF fails.

~all vs -all

~all soft-fails unlisted senders, -all fails them. With DMARC enforced, either works; +all and ?all protect nothing.

FAQ

Common questions.

How do I fix "too many DNS lookups"?

Remove includes for services you no longer use, replace a and mx with the ip4 ranges they resolve to if those are stable, and move bulk-sending platforms onto their own subdomain (for example news.example.com) with its own SPF record. Avoid automatic "flattening" services unless they track your providers' changes.

Should I use ~all or -all?

Either is fine once DMARC is enforced, because DMARC decides what happens to failing mail. ~all is the safer default: forwarded mail fails SPF, and some receivers reject outright on -all before DMARC is even considered.

Do I need an SPF record on subdomains?

SPF is not inherited. Each hostname that appears as an envelope sender needs its own record. A subdomain that never sends mail can publish v=spf1 -all so nobody can use it.

Why does my SPF pass but DMARC fail?

SPF passed for the Return-Path domain, but that domain belongs to your sending platform, not to your From domain, so it does not align. Set up a custom return path (a bounce domain on your own domain) or rely on DKIM alignment.

For agents and pipelines

The same check, as an API and an MCP tool.

Point an MCP client (Claude, Cursor, any agent) at https://powerline.ai/mcp and call check_record, or hit the JSON endpoint directly. No key, no account.

spf.sh
curl "https://powerline.ai/api/tools/spf?domain=example.com"
More free tools

Keep going.

DMARC Checker

Read the DMARC policy, alignment and reporting tags, and check that report addresses will accept reports.

DKIM Checker

Find the DKIM public key for a selector (or auto-detect common ones) and check its size and flags.

Email Domain Check

SPF, DKIM, DMARC, MX, MTA-STS, TLS-RPT, BIMI and blacklists in one run, scored out of 100 with a fix list.

Email Header Analyzer

Trace a message hop by hop, read the receiver's SPF/DKIM/DMARC verdicts and check DMARC alignment.

Inbox Preview

See how your HTML email actually renders in real Gmail, Outlook.com and Yahoo Mail accounts. Free screenshots.

All email tools