Instantly retrieve and parse the SPF (Sender Policy Framework) record for any domain. View all mechanisms, qualifiers, DNS lookup count, and syntax validation — free, browser-only, no signup.
✍️ Author: ToolsNovaHub•📅 Last Updated: 14 September 2026
Examples:
gmail.commicrosoft.comgithub.com
🔄 Querying SPF record…
🔒 SPF Status
📊 SPF Statistics
DNS Lookup Count—
Mechanism Count—
All Qualifier—
Record Length—
📜 Raw SPF Record
📋 Parsed Mechanisms
Qualifier
Mechanism
Value
Action
DNS Lookup
⚠️ Warnings & Recommendations
🔎 Full DNS Response
🕒 Recent Lookups
No recent lookups yet.
📚 What Is an SPF Record?
SPF (Sender Policy Framework), defined in RFC 7208, is an email authentication protocol that lets domain owners publish a list of authorized sending IP addresses in DNS as a TXT record. When a receiving mail server gets a message claiming to be from user@example.com, it queries DNS for example.com's SPF record and checks whether the sending IP is authorized.
SPF prevents email spoofing — attackers forging the sender address to impersonate legitimate domains. Without SPF, anyone can send email claiming to be from your domain. With a strict SPF policy (-all), unauthorized senders are blocked outright.
🔄 SPF Mechanisms Explained
Mechanism
Description
DNS Lookup?
Example
ip4:
Authorize a single IPv4 or CIDR range
No
ip4:203.0.113.0/24
ip6:
Authorize a single IPv6 or CIDR range
No
ip6:2001:db8::/32
a:
Authorize the A record IPs of a hostname
Yes
a:mail.example.com
mx:
Authorize the A records of MX hosts
Yes
mx:example.com
include:
Delegate to another domain's SPF record
Yes
include:_spf.google.com
redirect=
Replace entire policy with another domain's SPF
Yes
redirect=_spf.example.net
exists:
Match if the given hostname resolves
Yes
exists:%{i}.spf.example.com
ptr:
Match if rDNS hostname ends with given domain (deprecated)
Yes
ptr:example.com
all
Always match — used as final catch-all
No
-all
🔑 SPF Qualifiers
✅
+ Pass (default)
The sending IP is authorized. Email should be accepted. + is the default qualifier and is usually omitted. Example: +ip4:203.0.113.1 or just ip4:203.0.113.1.
❌
- Fail (Hardfail)
The sending IP is NOT authorized. The receiving server should reject the message. Best practice for security. Example: -all at end of record.
⚠️
~ SoftFail
The IP is not authorized but the domain owner asks servers to accept and mark. Used during transitions. Gmail typically puts softfail messages in spam. Example: ~all.
❓
? Neutral
No assertion about authorization. Functionally equivalent to having no SPF policy — not recommended for production use. Example: ?all.
🔧 Troubleshooting
⚠️ No SPF record found
If the domain sends email at all, this is worth fixing — without an SPF record, receiving servers have no baseline to check against, which can hurt deliverability even before DKIM/DMARC are considered.
⚠️ "Too many DNS lookups" error
SPF's RFC 7208 hard limit is 10 DNS-querying mechanisms (include, a, mx, ptr, exists, redirect) per evaluation. Nested includes from nested SPF records count too — this tool flags the total so you can see how close you are to the ceiling.
⚠️ Multiple SPF records on one domain
A domain must have exactly one SPF (TXT starting with v=spf1). Two or more causes a PermError under the spec, which many receiving servers treat as an outright authentication failure rather than a partial pass.
⚠️ Legitimate mail still failing SPF
Check whether the sending IP is actually inside every included range, and whether a recent change to your email provider's infrastructure added a new sending IP the record hasn't been updated for yet.
🛡️ Use Cases for SPF Lookup
📧
Email Deliverability Troubleshooting
Emails going to spam? Check SPF first. A missing, misconfigured, or too-permissive SPF record is a top cause of deliverability failures and spam classification.
📊
DNS Lookup Count Audit
SPF is limited to 10 DNS lookups per evaluation. Exceeding this causes PermError — which looks like SPF fail to receiving servers. Use this tool to count lookups and identify which includes to flatten.
🔍
Security Research / Phishing Simulation
Security teams check target domain SPF policies to understand email controls. A weak ?all or missing SPF makes a domain trivially spoofable — an immediate red flag in any email security audit.
🔄
Email Provider Migration
When switching from one email provider to another, update SPF includes and verify with this tool before updating MX records. Use our MX Lookup tool to confirm MX records are also correct.
🔗 More Ways to Investigate Email Authentication
For full email server configuration, check MX Lookup. For complete domain DNS investigation, use DNS Lookup. For email address validation including SPF check, use Email Checker. Learn the complete email authentication picture in our blog: SPF Record Complete Guide. Also see What Is an IP Address? to understand the IPs SPF authorizes.
ToolsNovaHub tools are built and independently maintained with a focus on accurate, no-signup network and security utilities. Spotted an error? Let us know.
🎓
Expert Tip
DNS and mail records can take up to 48 hours to fully propagate — if SPF Lookup shows an unexpected result right after a change, wait and re-check before assuming misconfiguration.
⭐
ToolsNovaHub Pro Tip
Run SPF Lookup from more than one network (office Wi-Fi + mobile data) to rule out local resolver caching before reporting a bug.
⚠️
Common Beginner Mistake
Editing a live DNS or mail record without noting the previous value first. Always save the old record from SPF Lookup's output so you can roll back instantly if something breaks.
What is the difference between SPF, DKIM, and DMARC? +
SPF validates the sending IP. DKIM adds a cryptographic signature verified against a public key in DNS. DMARC ties both together, letting owners specify actions (none/quarantine/reject) when SPF or DKIM fails.
What does SPF pass mean? +
SPF pass means the sending IP matched an authorized mechanism. The email appears to come from an IP the domain owner approved — the desired outcome.
What does SPF fail mean? +
SPF fail (hardfail, -all) means the sending IP is not authorized. Depending on DMARC policy and the receiving server's configuration, the email may be rejected outright.
What is SPF softfail? +
SPF softfail (~all) means the sending IP is not authorized, but the domain owner recommends accepting and marking as suspicious. Gmail typically delivers softfail email to spam.
What is an SPF redirect modifier? +
redirect= replaces the entire SPF evaluation with another domain's SPF policy. Unlike include:, it must be the only mechanism and replaces all other mechanisms. Used when a third party manages your email policy entirely.
How do I add an SPF record? +
In your DNS panel, add a TXT record at @ (root domain) with value like: v=spf1 include:_spf.google.com -all. Replace the include with your email provider's SPF include. Changes take effect after TTL expires (typically 1 hour).
How do I check SPF with dig? +
Run: dig TXT example.com +short | grep spf (Linux/Mac) or Resolve-DnsName example.com -Type TXT (Windows). This tool replicates that query in your browser with full parsing.
Is SPF Lookup free? +
Yes — completely free, no sign-up needed, and we don't cap normal usage. Queries go through Google's public DNS-over-HTTPS resolver, which may itself rate-limit unusually heavy or automated traffic, but results otherwise appear instantly.