← All tools

Free DNS tool

SPF Checker

Find the SPF record authorizing mail senders for a domain.

These lookups show published DNS records. They do not verify inbox deliverability or prove that an email passes authentication.

Understand the lookup

What this checker is really showing

SPF is a DNS policy for the servers allowed to send using a domain in the SMTP envelope. This checker finds the domain’s SPF TXT record so you can inspect its mechanisms and final rule.

Illustrative DNS record

example.com TXT "v=spf1 include:_spf.example.net -all"
SPF specification (RFC 7208) ↗

A useful way to check

  1. 1Enter the domain used in your return-path or MAIL FROM address.
  2. 2Look through each ip4, ip6, a, mx, include, or redirect term for a sender you recognize.
  3. 3Review the ending rule and test actual messages before removing a sender.

Read the result

Details worth noticing

include: / redirect=

These delegate SPF evaluation to another domain. They are common for mail providers and can require extra DNS lookups.

-all / ~all / +all

These describe the outcome for senders not matched earlier: fail, softfail, or pass. +all effectively allows everyone.

One SPF record

Publish one TXT record beginning with v=spf1. Multiple such records cause an SPF evaluation error.

Before you change a record

  • This lookup does not recursively evaluate includes or calculate the complete DNS-lookup cost.
  • SPF checks the envelope identity; it does not by itself authenticate the visible From address.
  • An SPF record can exist while a real message still fails because it came from an unlisted sender.

Quick answers

Why do I see other TXT records?

Domains can publish TXT for several purposes. The checker isolates records starting with v=spf1 and leaves unrelated TXT values out of the SPF result.

Does finding an SPF record mean my mail is authorized?

Not necessarily. Authorization depends on the connecting IP, the envelope domain, and the full SPF evaluation for that specific message.