SPF Record Analyzer
Paste an SPF record (or fetch one by domain) to break down every mechanism, check syntax against RFC 7208, and count your DNS lookups against the hard limit of 10. Parsed in your browser; the only network request is the optional DNS lookup via Google Public DNS.
Record
Mechanisms
| Term | Lookups | Meaning |
|---|---|---|
| +include:_spf.google.com | 1 | Evaluate the SPF record of another domain and pass if it passes. Costs a DNS lookup. |
| +include:spf.protection.outlook.com | 1 | Evaluate the SPF record of another domain and pass if it passes. Costs a DNS lookup. |
| +include:mailgun.org | 1 | Evaluate the SPF record of another domain and pass if it passes. Costs a DNS lookup. |
| +ip4:203.0.113.10/29 | 0 | IPv4 address or range allowed to send. |
| -all | 0 | Matches everything (must be last). -all = hard fail, ~all = soft fail, +all = allow all (never do this). |
Findings
About SPF
SPF (Sender Policy Framework, RFC 7208) lists the servers allowed to send email for your domain, published as a TXT record. Receivers check it before accepting mail. It is one leg of email authentication, alongside DKIM (cryptographic signatures) and DMARC (the policy tying both together — try our DMARC parser).
The 10-lookup limit is the classic killer: every include chain is walked by the receiver, and past 10 lookups your SPF simply errors out and stops protecting anything. The fix is flattening — replacing includes with their underlying ip4/ip6 blocks.