Check any domain's SPF record

See which servers a domain authorizes to send its email, and whether the record holds up.

What you get

Mechanisms parsed

Every include, ip4, ip6, a, mx, exists, and redirect term is listed as its own row, so you can read the policy without decoding the raw string.

All qualifier explained

The record's -all, ~all, ?all, or +all ending is graded, since +all lets anyone pass SPF and softfail is weaker than hardfail.

Lookup count checked

DNS-querying terms are counted against the RFC 7208 limit of 10, past which receivers return permerror and stop evaluating the record.

Need more than a demo?

Create a free account and get 100 API credits to use across every endpoint.

Want the full power? See the full API

100 free creditsNo credit card