Sender Policy Framework lookup
SPF Record Checker: Look Up and Read Your Policy
Fetch the published v=spf1 record for a sending domain, read its mechanisms in order, and count the DNS-querying terms visible at the top level.
How to read the record
SPF authorizes sending infrastructure by IP address, include, or redirect. The all mechanism defines the default verdict for unmatched senders. Mechanisms evaluate left to right, and the first match ends evaluation.
The 10-lookup limit
Each include, a, mx, ptr, exists, or redirect term forces more DNS queries during evaluation. RFC 7208 caps the complete evaluation at 10 public DNS lookups; exceeding it produces permerror regardless of the policy text.
One record, one domain
A domain should publish exactly one selectable v=spf1 record. If two providers each publish their own record, combine the terms into one policy instead of keeping both.
Questions about this tool
Does an SPF record prove my email reaches the inbox?
No. SPF publishes authorization policy for the domain. Inbox placement depends on authentication alignment, sending reputation, content, and the receiving provider's filters.
Why did the checker report a lookup budget risk?
The top-level DNS-querying terms approach or exceed the 10-lookup evaluation cap in RFC 7208. Flatten or split the include chain before senders hit permerror.
Can I check SPF for a subdomain?
Yes. Enter the subdomain itself. SPF has no parent-domain fallback: receivers check only the exact name used in MAIL FROM or HELO, so every subdomain that sends mail needs its own v=spf1 record.