Back to Tools

SPF Record Checker

Ensure your domain is properly authenticated with our SPF record checker. Avoid spoofing and improve inbox placement.

About this tool

SPF (Sender Policy Framework) tells receiving mail servers which IP addresses are allowed to send email from your domain. Without it, anyone can forge your "From" address, and inbox providers have no way to tell the difference between your real emails and a phishing attack using your name. Gmail, Microsoft, and Yahoo now require SPF authentication — if your record is missing or broken, your emails are going to spam.

How SPF records work

An SPF record is a DNS TXT entry on your domain that lists every server authorized to send on your behalf. When a receiving server gets an email from your domain, it looks up your SPF record and checks if the sending server's IP is on the list. If it matches, the email passes SPF. If it doesn't, the server can reject it, flag it as spam, or let it through depending on your policy (the -all vs ~all setting at the end of the record). A typical SPF record looks like: v=spf1 include:_spf.google.com include:sendgrid.net -all.

Why this matters for email marketers

As of early 2024, Gmail and Yahoo require bulk senders (5,000+ emails/day) to have valid SPF, DKIM, and DMARC records. Even if you're below that threshold, SPF directly impacts whether your campaigns reach the inbox or the spam folder. A missing or misconfigured SPF record is one of the most common — and most fixable — causes of deliverability problems. Fixing it often produces an immediate, measurable improvement in inbox placement.

Common mistakes to avoid

The most frequent SPF mistake is exceeding the 10 DNS lookup limit. Every include, a, mx, and redirect mechanism in your record counts as one lookup, and the includes can be nested (an include that itself has 3 includes uses 4 lookups). Go over 10 and the entire record fails, which is worse than having no SPF at all. Use our SPF flattener if you're hitting the limit. Another common mistake is having multiple SPF records on the same domain — you can only have one TXT record starting with v=spf1. Finally, don't forget to include all your sending services: your email marketing platform, your transactional email provider, Google Workspace, and any other tool that sends email from your domain.

How to use this with your email workflow

Start by running your domain through this checker to see your current SPF status. If you don't have a record, use our SPF generator to create one. After publishing the record, verify it propagated with our DNS propagation checker — DNS changes can take up to 48 hours to spread globally. Once SPF is working, move on to DKIM and DMARC to complete the authentication trifecta. Check your overall deliverability score before and after to measure the impact.

Frequently Asked Questions

What is an SPF record?

It's a DNS TXT record that lists every mail server authorized to send email from your domain. Receiving servers check this record to verify that incoming emails actually came from an approved source. Without it, there's no way for recipients to distinguish your legitimate emails from spoofed ones.

Why do I need an SPF record?

Gmail, Yahoo, and Microsoft now require SPF for bulk senders. Even for smaller senders, a missing SPF record means recipient servers can't verify you, which significantly increases your chances of landing in spam. It's one of the easiest deliverability wins you can get — usually takes about 10 minutes to set up.

What does 'too many DNS lookups' mean?

The SPF specification limits you to 10 DNS lookups per record. Each include, a, mx, and redirect mechanism counts as one, and nested includes count too. If your record requires 11 or more lookups, it fails entirely — called a "permerror" — which is worse than having no SPF at all. Use our SPF flattener tool to reduce lookup count by converting includes to direct IP ranges.

What is the difference between ~all and -all?

-all (hard fail) tells receiving servers to reject any email from your domain that doesn't match your SPF record. ~all (soft fail) says to flag it as suspicious but still potentially deliver it. Start with ~all while you're setting up and testing, then switch to -all once you've confirmed all your legitimate sending sources are included.

Can I have multiple SPF records on one domain?

No. The SPF spec requires exactly one SPF TXT record per domain. If you have two, both will fail. This is a surprisingly common mistake — when adding a new email service, people sometimes create a second SPF record instead of adding an include to the existing one. Merge everything into a single record.

How long does it take for SPF changes to take effect?

DNS changes typically propagate within 1-4 hours, but can take up to 48 hours depending on your DNS provider's TTL settings and global DNS cache refresh cycles. During this window, some servers will see the old record and others will see the new one. Don't panic if results are inconsistent for the first day.

Does SPF alone prevent email spoofing?

SPF only verifies the envelope sender (the Return-Path), not the header From address that recipients actually see. A spoofer can still forge the visible From address while using a different envelope sender. To fully prevent spoofing, you need SPF plus DKIM plus a DMARC policy set to reject or quarantine. The three work together as a system.

What's the difference between SPF, DKIM, and DMARC?

SPF says which servers can send from your domain. DKIM cryptographically signs each email to prove it wasn't tampered with in transit. DMARC ties them together with a policy that tells receivers what to do when SPF or DKIM fail, and gives you reporting on authentication results. You need all three for proper email authentication.

My SPF record is valid but emails still go to spam. Why?

SPF is necessary but not sufficient. Spam filtering considers hundreds of signals including content quality, sender reputation, engagement history, and whether you have DKIM and DMARC set up too. A valid SPF record gets you past one checkpoint, but you still need good content, a clean list, and complete authentication to consistently hit the inbox.

Compare email marketing software

Hands-on roundups to help you pick the right platform.