SPF record checker
Validate a domain's SPF record, count its DNS lookups through every include, and get a fix you can paste. Free, no signup.
What this SPF check looks at
- Exactly one TXT record starting with
v=spf1(two or more is a permanent error). - The final
allrule:-allor~allpass,?allor a missing all is a warning,+allfails. - The 10 DNS-lookup limit: every
include:,a,mx,ptr,existsandredirect=counts, including the ones nested inside your includes. Above 10, SPF fails for every message. - Broken includes that point to a domain without a single valid SPF record.
Frequently asked questions
What is an SPF record?
SPF (Sender Policy Framework) is a DNS TXT record that lists the servers and services allowed to send email for your domain, for example v=spf1 include:_spf.google.com ~all. Receivers compare the sending server with this list.
Should I use ~all or -all?
Both are fine. ~all (soft fail) is the common choice, and once DMARC is enforced, receivers act on the DMARC policy anyway. -all (hard fail) is stricter and suits domains that are sure every sender is listed, or that never send email at all.
What is the SPF 10-lookup limit?
RFC 7208 limits SPF evaluation to 10 DNS-querying mechanisms (include, a, mx, ptr, exists, redirect), counted recursively. Going over causes a "permerror", and many receivers treat the message as failing SPF. Remove unused services or replace includes with ip4:/ip6: ranges.
Can I have two SPF records?
No. A domain must have only one SPF record. If you add a new email service, add its include to the existing record instead of creating a second one.
My domain does not send email. Do I need SPF?
Yes, it is good practice: publish v=spf1 -all so nobody can pass SPF as your domain, together with a DMARC record set to p=reject.
Does SPF alone stop spoofing?
No. SPF checks the hidden envelope sender, not the From address people see. DMARC ties SPF and DKIM to the visible From domain, so you need DMARC to actually stop spoofing.
How StackGrade works
Email authentication · 50 pts
SPF (including the 10-lookup limit), DMARC policy, DKIM keys at common selectors, and MX. These decide whether Gmail and Yahoo trust your mail, and whether scammers can spoof you.
Website security · 35 pts
HTTPS redirect, HSTS, Content-Security-Policy, clickjacking protection, X-Content-Type-Options, Referrer-Policy and cookie flags, using Mozilla's public HTTP Observatory scan.
Domain health · 15 pts
Expiry date and registrar transfer lock from the official registry (RDAP). Domain age, email provider, tech stack and hiring signals are shown but not scored.
Honest by design
If a check can't run (the registry has no RDAP, the site blocks scanners, a lookup times out), we show Not checked with the reason and leave it out of the score. We never guess. The full rubric is public.
Privacy
The checks run in your browser, which asks public services directly: Google Public DNS / Cloudflare DNS, the domain's registry RDAP server, Mozilla HTTP Observatory (its scan history is public) and public job boards (Greenhouse, Lever, Ashby, Workable). For the tech-stack scan, the StackGrade API fetches the site's public homepage; the result is kept briefly in memory, never stored. Graded domains are not logged. Details in the privacy policy. Page views are counted with GoatCounter (open source, no cookies, no personal data); only the page path is sent, never the domain you check.