Skip to main content

SPF Record Analyzer

Paste an SPF record (or fetch one by domain) to break down every mechanism, check syntax against RFC 7208, and count your DNS lookups against the hard limit of 10. Parsed in your browser; the only network request is the optional DNS lookup via Google Public DNS.

Record

3/10
DNS lookups used
include, a, mx, ptr, exists and redirect each cost 1

Mechanisms

TermLookupsMeaning
+include:_spf.google.com1Evaluate the SPF record of another domain and pass if it passes. Costs a DNS lookup.
+include:spf.protection.outlook.com1Evaluate the SPF record of another domain and pass if it passes. Costs a DNS lookup.
+include:mailgun.org1Evaluate the SPF record of another domain and pass if it passes. Costs a DNS lookup.
+ip4:203.0.113.10/290IPv4 address or range allowed to send.
-all0Matches everything (must be last). -all = hard fail, ~all = soft fail, +all = allow all (never do this).

Findings

Mechanism "include" appears 3 times — consolidate duplicates to save lookups.
3/10 DNS lookups used.

About SPF

SPF (Sender Policy Framework, RFC 7208) lists the servers allowed to send email for your domain, published as a TXT record. Receivers check it before accepting mail. It is one leg of email authentication, alongside DKIM (cryptographic signatures) and DMARC (the policy tying both together — try our DMARC parser).

The 10-lookup limit is the classic killer: every include chain is walked by the receiver, and past 10 lookups your SPF simply errors out and stops protecting anything. The fix is flattening — replacing includes with their underlying ip4/ip6 blocks.