Your browser asks Google Public DNS directly for the domain’s public records. Nothing is sent to this site and nothing is stored; only an anonymous count of checks is kept.
What SPF does
SPF (Sender Policy Framework) is a DNS TXT record that lists the servers allowed to send email for your domain. The server that receives a message compares the sender with that list. You need exactly one record, and it starts with v=spf1.
The limit of 10 DNS lookups
Each include, a, mx, ptr, exists, and redirect counts, including those inside included records. ip4 and ip6 addresses do not count. Above 10, SPF fails (PermError) and your email may land in spam. To get back under 10:
- Remove services you no longer use.
- Replace an include with ip4 or ip6 addresses only if the provider keeps the same addresses.
- Send the newsletter from a subdomain that has its own SPF record.
- Only “flatten” SPF with a tool that keeps it updated: a fixed copy goes stale.
~all or -all?
- -all (fail): mail from a server that is not listed is rejected.
- ~all (softfail): it is marked suspicious. A good starting point.
- ?all (neutral): no protection.
- +all: everyone is allowed. Never use it.
Start with ~all and move to -all once your DMARC reports are clean.
Typical records
- Microsoft 365: v=spf1 include:spf.protection.outlook.com -all
- Google Workspace: v=spf1 include:_spf.google.com ~all
These are examples: add the other services that send in your name, inside the same record.
Frequently asked questions
Can I have two SPF records?
No. Two SPF records make the check fail. Merge them into one.
My SPF passes but my email still goes to spam. Why?
SPF is only one signal. DKIM, DMARC, domain reputation, and content matter too. Run the full check.
Is SPF enough against spoofing?
No. SPF checks the technical sender, not the visible address. DMARC ties the two together. Use SPF, DKIM, and DMARC together.
The other checkers
The tool reads public DNS records only and cannot see your messages. Built in Montreal by Yazan Rajabi.