Paste an SPF record and instantly validate its syntax, mechanisms, DNS lookup count, and terminal policy — before or after you publish it.
Paste the SPF TXT value exactly as your DNS provider or lookup tool shows it. Include targets are listed but never contacted.
Private by design: the record is parsed entirely in your browser. No DNS lookups are made and nothing you paste is sent to or stored on a server.
Copy the SPF value from your DNS provider or a lookup tool and paste it in. Surrounding quotes are stripped automatically; everything else is checked exactly as written.
Each mechanism and modifier is explained in evaluation order, with its qualifier, whether it costs a DNS lookup, and any syntax error at that exact position.
Findings are listed by severity with concrete fixes. Edit the text and run the check again until the record parses cleanly, then publish a single TXT record.
Check the live SPF record of any domain, including nested includes, lookup counts, and void lookups over real DNS.
Open toolBuild a correct SPF record from your sending services with guided inputs, then publish it as a single TXT record.
Open toolValidate your DMARC policy, alignment modes, and reporting addresses against the current RFC 9989 specification.
Open toolThe SPF Checker looks up a domain’s live DNS records and follows include chains. This raw checker validates text you paste yourself, so it is ideal for reviewing a record before you publish it — but it never expands include or redirect targets because it performs no DNS queries.
No. The record is parsed entirely in your browser with the same SPF parser our server-side checker uses. Nothing is uploaded, logged, or stored.
RFC 7208 limits SPF evaluation to 10 DNS-querying mechanisms and modifiers (include, a, mx, ptr, exists, and redirect). This tool counts the terms in the pasted record only; includes can hide additional lookups, so verify the total with the SPF Checker after publishing.
-all (fail) rejects unauthorized senders outright, ~all (softfail) marks them as suspicious, and ?all (neutral) offers no spoofing protection. Most senders start with ~all while they confirm every legitimate source is listed, then move to -all. Never use +all — it authorizes the entire internet to send as your domain.
Syntax validity is only one part of SPF. A record can parse perfectly and still fail evaluation because an include target is missing, the 10-lookup limit is exceeded once nested includes are counted, or the sending service uses a different envelope domain. Always validate the published record with a live DNS check too.
Automate Sales Outreach & Get Booked!
Start Free Trial(14 Day Free Trial, No CC Required)