StackGrade

SPF record checker

Validate a domain's SPF record, count its DNS lookups through every include, and get a fix you can paste. Free, no signup.

Try: github.com stripe.com bbc.co.uk example.com

What this SPF check looks at

Frequently asked questions

What is an SPF record?

SPF (Sender Policy Framework) is a DNS TXT record that lists the servers and services allowed to send email for your domain, for example v=spf1 include:_spf.google.com ~all. Receivers compare the sending server with this list.

Should I use ~all or -all?

Both are fine. ~all (soft fail) is the common choice, and once DMARC is enforced, receivers act on the DMARC policy anyway. -all (hard fail) is stricter and suits domains that are sure every sender is listed, or that never send email at all.

What is the SPF 10-lookup limit?

RFC 7208 limits SPF evaluation to 10 DNS-querying mechanisms (include, a, mx, ptr, exists, redirect), counted recursively. Going over causes a "permerror", and many receivers treat the message as failing SPF. Remove unused services or replace includes with ip4:/ip6: ranges.

Can I have two SPF records?

No. A domain must have only one SPF record. If you add a new email service, add its include to the existing record instead of creating a second one.

My domain does not send email. Do I need SPF?

Yes, it is good practice: publish v=spf1 -all so nobody can pass SPF as your domain, together with a DMARC record set to p=reject.

Does SPF alone stop spoofing?

No. SPF checks the hidden envelope sender, not the From address people see. DMARC ties SPF and DKIM to the visible From domain, so you need DMARC to actually stop spoofing.

How StackGrade works

Email authentication · 50 pts

SPF (including the 10-lookup limit), DMARC policy, DKIM keys at common selectors, and MX. These decide whether Gmail and Yahoo trust your mail, and whether scammers can spoof you.

Website security · 35 pts

HTTPS redirect, HSTS, Content-Security-Policy, clickjacking protection, X-Content-Type-Options, Referrer-Policy and cookie flags, using Mozilla's public HTTP Observatory scan.

Domain health · 15 pts

Expiry date and registrar transfer lock from the official registry (RDAP). Domain age, email provider, tech stack and hiring signals are shown but not scored.

Honest by design

If a check can't run (the registry has no RDAP, the site blocks scanners, a lookup times out), we show Not checked with the reason and leave it out of the score. We never guess. The full rubric is public.

Privacy

The checks run in your browser, which asks public services directly: Google Public DNS / Cloudflare DNS, the domain's registry RDAP server, Mozilla HTTP Observatory (its scan history is public) and public job boards (Greenhouse, Lever, Ashby, Workable). For the tech-stack scan, the StackGrade API fetches the site's public homepage; the result is kept briefly in memory, never stored. Graded domains are not logged. Details in the privacy policy. Page views are counted with GoatCounter (open source, no cookies, no personal data); only the page path is sent, never the domain you check.