ActiScan

SPF Record Checker

Instantly check any domain's SPF record and whether it's enforced (-all) or leaving the door open.

Need to monitor this across every client domain you manage? ActiScan does bulk scanning, scoring, and white-labeled reporting for MSPs.

How to Use the SPF Checker

1

Enter a domain

No http:// prefix – just the domain itself (e.g. company.com).

2

Click Check

ActiScan looks up the domain's TXT records live, over DNS, and finds the v=spf1 entry.

3

Read the result

A pass/warn/fail status plus a plain-English explanation of what to do next.

What Your Result Means

-allPass

Hard fail. Mail from servers not listed in the record is rejected outright by receivers that enforce SPF. This is the optimal configuration.

~all or no enforcementWarn

~all (soft fail) tells receivers to accept but flag unauthorized mail – a transition step, not a destination. A record with no -all or ~all at all (neutral ?all, +all, or nothing) exists but enforces nothing.

No record foundFail

The domain publishes no SPF record. Any server can send email claiming to be from your domain, with no authorized-sender list for receivers to check against.

What is an SPF Record?

SPF (Sender Policy Framework) is a DNS TXT record that lists which mail servers are authorized to send email on behalf of your domain. Receiving mail servers check the sending server's IP address against that list and decide what to do with mail that doesn't match.

It's published as a TXT record at your domain's root – for example.com, that's example.com itself, not a subdomain. When mail claiming to be from your domain arrives somewhere, the receiving server looks up your domain's TXT records, finds the one starting with v=spf1, evaluates each mechanism in order until one matches the sending IP, and applies that mechanism's qualifier – or falls through to the trailing all mechanism if nothing matches.

SPF Record Examples

Single provider, enforced

v=spf1 include:_spf.google.com -all

Authorizes only Google Workspace's mail servers and hard-fails everything else – a clean, fully enforced record.

Multiple providers

v=spf1 include:_spf.google.com include:sendgrid.net -all

Stacks two include: mechanisms so both Google Workspace and SendGrid can send as the domain, still hard-failing anything else.

Soft fail during migration

v=spf1 include:_spf.google.com ~all

Same authorized senders, but ~all only flags unauthorized mail instead of blocking it – useful while you confirm every legitimate sender is listed.

Need to build your own? Use the free SPF generator.

SPF Mechanisms Explained

MechanismWhat it doesExampleNotes
v=spf1Protocol version. Must be the first term.v=spf1Required
ip4 / ip6Authorizes a specific IPv4 or IPv6 address or CIDR range.ip4:203.0.113.5Optional
aAuthorizes the domain's own A/AAAA record IP(s).a or a:mail.example.comOptional
mxAuthorizes the domain's MX hosts' IP(s).mxOptional
includePulls in another domain's SPF record – how most mail providers get authorized.include:_spf.google.comOptional (counts toward the lookup limit)
redirectDelegates the entire evaluation to another domain's SPF record.redirect=example.netOptional (counts toward the lookup limit)
allCatch-all for anything not matched above. Always the last term.-all / ~all / ?allRequired (should be last)

The qualifier in front of all (or any mechanism) controls what happens on a match: - (fail), ~ (soft fail), ? (neutral), or + (pass – the default if omitted).

How to Find Your SPF Record Manually

If you'd rather look it up yourself instead of using the checker above:

Using nslookup

nslookup -type=TXT yourdomain.com

Using dig

dig TXT yourdomain.com

Next Steps After Your Check

No record found?

Build a valid one in under a minute, no manual editing required.

SPF Generator →

Using ~all? Move toward -all.

ActiScan tracks your enforcement level over time and flags when you're ready to tighten it.

Start free →

Want ongoing monitoring?

ActiScan scans on a schedule and alerts you when something changes – across every domain you manage.

Start free →

Frequently Asked Questions

Is this SPF checker free?

Yes – check any domain's SPF record for free, no signup required.

Do I need to own the domain I'm checking?

No. SPF records are published in public DNS, so anyone can look one up.

What's the difference between -all and ~all?

-all is a hard fail: receivers that enforce SPF reject unauthorized mail outright. ~all is a soft fail: unauthorized mail is typically accepted but flagged or scored down. -all is the stronger, recommended setting once you're confident every legitimate sender is listed.

Can a domain have more than one SPF record?

No. RFC 7208 requires exactly one SPF TXT record per domain – multiple v=spf1 records cause receivers to treat SPF as a permanent error. Merge all your senders into a single record instead.

What's the 10-lookup limit I keep hearing about?

RFC 7208 caps SPF evaluation at 10 DNS lookups, counting include, a, mx, ptr, exists, and redirect mechanisms. Stack enough providers' include: mechanisms and you can exceed it, which causes receivers to treat the record as a permanent error – effectively the same as having no SPF at all.

Use the free SPF checker as often as you need

Start free trial