ActiScan
← Email Authentication Fundamentals

Module 2 of 6

SPF — What It Checks and How It Fails

SPF (Sender Policy Framework) is a DNS TXT record that lists which mail servers are allowed to send using your domain in the SMTP envelope.

A real record

v=spf1 include:_spf.google.com include:mailgun.org ~all

Reading left to right:

  • v=spf1 – this is an SPF record, version 1 (the only version that exists).
  • include:_spf.google.com – trust whatever servers Google Workspace's own SPF record authorizes.
  • include:mailgun.org – also trust Mailgun's sending infrastructure (a common pattern for transactional email).
  • ~all – softfail: anything not covered above should be treated as suspicious, but not outright rejected.

Other common mechanisms: a (the domain's own A record), mx (its mail servers), ip4/ip6 (specific addresses). The qualifier at the end matters: -all (hardfail – reject) is meaningfully stronger than ~all (softfail) or ?all (neutral, effectively meaningless).

The 10-lookup limit – a real, common failure

RFC 7208 caps SPF evaluation at 10 DNS lookups per check, counting every include, a, mx, exists, and redirect mechanism, recursively. Add a fourth or fifth vendor include (CRM, helpdesk, marketing platform, each with their own nested includes) and it's easy to blow past 10 without anyone noticing – until SPF starts returning permerror and receiving servers can no longer evaluate it at all. This is one of the single most common real-world SPF failures, and it's invisible until you actually count the lookups.

What SPF does not check

This is the detail almost everyone misses: SPF validates the envelope sender (MAIL FROM) – not the visible header From: address a person reads. A message can pass SPF perfectly while showing a completely different, spoofed From: header, because SPF was never checking that field to begin with.

That gap is exactly why DMARC exists – it's the mechanism that ties an SPF (or DKIM) result back to the header a human actually sees. More on that in Module 4.

Try ActiScan's SPF checker on your own domain, and the raw SPF checker on a record you haven't published yet, to see the lookup count before you publish it.

Try it yourself: SPF Record Checker