SPF Record Checker
Instantly check any domain's SPF record and whether it's enforced (-all) or leaving the door open.
Need to monitor this across every client domain you manage? ActiScan does bulk scanning, scoring, and white-labeled reporting for MSPs.
How to Use the SPF Checker
Enter a domain
No http:// prefix – just the domain itself (e.g. company.com).
Click Check
ActiScan looks up the domain's TXT records live, over DNS, and finds the v=spf1 entry.
Read the result
A pass/warn/fail status plus a plain-English explanation of what to do next.
What Your Result Means
-allPassHard fail. Mail from servers not listed in the record is rejected outright by receivers that enforce SPF. This is the optimal configuration.
~all or no enforcementWarn~all (soft fail) tells receivers to accept but flag unauthorized mail – a transition step, not a destination. A record with no -all or ~all at all (neutral ?all, +all, or nothing) exists but enforces nothing.
No record foundFailThe domain publishes no SPF record. Any server can send email claiming to be from your domain, with no authorized-sender list for receivers to check against.
What is an SPF Record?
SPF (Sender Policy Framework) is a DNS TXT record that lists which mail servers are authorized to send email on behalf of your domain. Receiving mail servers check the sending server's IP address against that list and decide what to do with mail that doesn't match.
It's published as a TXT record at your domain's root – for example.com, that's example.com itself, not a subdomain. When mail claiming to be from your domain arrives somewhere, the receiving server looks up your domain's TXT records, finds the one starting with v=spf1, evaluates each mechanism in order until one matches the sending IP, and applies that mechanism's qualifier – or falls through to the trailing all mechanism if nothing matches.
SPF Record Examples
Single provider, enforced
v=spf1 include:_spf.google.com -all
Authorizes only Google Workspace's mail servers and hard-fails everything else – a clean, fully enforced record.
Multiple providers
v=spf1 include:_spf.google.com include:sendgrid.net -all
Stacks two include: mechanisms so both Google Workspace and SendGrid can send as the domain, still hard-failing anything else.
Soft fail during migration
v=spf1 include:_spf.google.com ~all
Same authorized senders, but ~all only flags unauthorized mail instead of blocking it – useful while you confirm every legitimate sender is listed.
Need to build your own? Use the free SPF generator.
SPF Mechanisms Explained
| Mechanism | What it does | Example | Notes |
|---|---|---|---|
| v=spf1 | Protocol version. Must be the first term. | v=spf1 | Required |
| ip4 / ip6 | Authorizes a specific IPv4 or IPv6 address or CIDR range. | ip4:203.0.113.5 | Optional |
| a | Authorizes the domain's own A/AAAA record IP(s). | a or a:mail.example.com | Optional |
| mx | Authorizes the domain's MX hosts' IP(s). | mx | Optional |
| include | Pulls in another domain's SPF record – how most mail providers get authorized. | include:_spf.google.com | Optional (counts toward the lookup limit) |
| redirect | Delegates the entire evaluation to another domain's SPF record. | redirect=example.net | Optional (counts toward the lookup limit) |
| all | Catch-all for anything not matched above. Always the last term. | -all / ~all / ?all | Required (should be last) |
The qualifier in front of all (or any mechanism) controls what happens on a match: - (fail), ~ (soft fail), ? (neutral), or + (pass – the default if omitted).
How to Find Your SPF Record Manually
If you'd rather look it up yourself instead of using the checker above:
Using nslookup
nslookup -type=TXT yourdomain.com
Using dig
dig TXT yourdomain.com
Next Steps After Your Check
Using ~all? Move toward -all.
ActiScan tracks your enforcement level over time and flags when you're ready to tighten it.
Start free →Want ongoing monitoring?
ActiScan scans on a schedule and alerts you when something changes – across every domain you manage.
Start free →Frequently Asked Questions
Is this SPF checker free?
Yes – check any domain's SPF record for free, no signup required.
Do I need to own the domain I'm checking?
No. SPF records are published in public DNS, so anyone can look one up.
What's the difference between -all and ~all?
-all is a hard fail: receivers that enforce SPF reject unauthorized mail outright. ~all is a soft fail: unauthorized mail is typically accepted but flagged or scored down. -all is the stronger, recommended setting once you're confident every legitimate sender is listed.
Can a domain have more than one SPF record?
No. RFC 7208 requires exactly one SPF TXT record per domain – multiple v=spf1 records cause receivers to treat SPF as a permanent error. Merge all your senders into a single record instead.
What's the 10-lookup limit I keep hearing about?
RFC 7208 caps SPF evaluation at 10 DNS lookups, counting include, a, mx, ptr, exists, and redirect mechanisms. Stack enough providers' include: mechanisms and you can exceed it, which causes receivers to treat the record as a permanent error – effectively the same as having no SPF at all.