🔒 SPF Lookup

Instantly retrieve and parse the SPF (Sender Policy Framework) record for any domain. View all mechanisms, qualifiers, DNS lookup count, and syntax validation — free, browser-only, no signup.

Examples: gmail.com   microsoft.com   github.com
🕒 Recent Lookups
No recent lookups yet.

📚 What Is an SPF Record?

SPF (Sender Policy Framework), defined in RFC 7208, is an email authentication protocol that lets domain owners publish a list of authorized sending IP addresses in DNS as a TXT record. When a receiving mail server gets a message claiming to be from user@example.com, it queries DNS for example.com's SPF record and checks whether the sending IP is authorized.

SPF prevents email spoofing — attackers forging the sender address to impersonate legitimate domains. Without SPF, anyone can send email claiming to be from your domain. With a strict SPF policy (-all), unauthorized senders are blocked outright.

🔄 SPF Mechanisms Explained

MechanismDescriptionDNS Lookup?Example
ip4:Authorize a single IPv4 or CIDR rangeNoip4:203.0.113.0/24
ip6:Authorize a single IPv6 or CIDR rangeNoip6:2001:db8::/32
a:Authorize the A record IPs of a hostnameYesa:mail.example.com
mx:Authorize the A records of MX hostsYesmx:example.com
include:Delegate to another domain's SPF recordYesinclude:_spf.google.com
redirect=Replace entire policy with another domain's SPFYesredirect=_spf.example.net
exists:Match if the given hostname resolvesYesexists:%{i}.spf.example.com
ptr:Match if rDNS hostname ends with given domain (deprecated)Yesptr:example.com
allAlways match — used as final catch-allNo-all

🔑 SPF Qualifiers

✅
+ Pass (default)
The sending IP is authorized. Email should be accepted. + is the default qualifier and is usually omitted. Example: +ip4:203.0.113.1 or just ip4:203.0.113.1.
❌
- Fail (Hardfail)
The sending IP is NOT authorized. The receiving server should reject the message. Best practice for security. Example: -all at end of record.
⚠️
~ SoftFail
The IP is not authorized but the domain owner asks servers to accept and mark. Used during transitions. Gmail typically puts softfail messages in spam. Example: ~all.
❓
? Neutral
No assertion about authorization. Functionally equivalent to having no SPF policy — not recommended for production use. Example: ?all.

🔧 Troubleshooting

⚠️ No SPF record found
If the domain sends email at all, this is worth fixing — without an SPF record, receiving servers have no baseline to check against, which can hurt deliverability even before DKIM/DMARC are considered.
⚠️ "Too many DNS lookups" error
SPF's RFC 7208 hard limit is 10 DNS-querying mechanisms (include, a, mx, ptr, exists, redirect) per evaluation. Nested includes from nested SPF records count too — this tool flags the total so you can see how close you are to the ceiling.
⚠️ Multiple SPF records on one domain
A domain must have exactly one SPF (TXT starting with v=spf1). Two or more causes a PermError under the spec, which many receiving servers treat as an outright authentication failure rather than a partial pass.
⚠️ Legitimate mail still failing SPF
Check whether the sending IP is actually inside every included range, and whether a recent change to your email provider's infrastructure added a new sending IP the record hasn't been updated for yet.

🛡️ Use Cases for SPF Lookup

📧
Email Deliverability Troubleshooting
Emails going to spam? Check SPF first. A missing, misconfigured, or too-permissive SPF record is a top cause of deliverability failures and spam classification.
📊
DNS Lookup Count Audit
SPF is limited to 10 DNS lookups per evaluation. Exceeding this causes PermError — which looks like SPF fail to receiving servers. Use this tool to count lookups and identify which includes to flatten.
🔍
Security Research / Phishing Simulation
Security teams check target domain SPF policies to understand email controls. A weak ?all or missing SPF makes a domain trivially spoofable — an immediate red flag in any email security audit.
🔄
Email Provider Migration
When switching from one email provider to another, update SPF includes and verify with this tool before updating MX records. Use our MX Lookup tool to confirm MX records are also correct.

🔗 More Ways to Investigate Email Authentication

For full email server configuration, check MX Lookup. For complete domain DNS investigation, use DNS Lookup. For email address validation including SPF check, use Email Checker. Learn the complete email authentication picture in our blog: SPF Record Complete Guide. Also see What Is an IP Address? to understand the IPs SPF authorizes.

ToolsNovaHub tools are built and independently maintained with a focus on accurate, no-signup network and security utilities. Spotted an error? Let us know.

🎓
Expert Tip
DNS and mail records can take up to 48 hours to fully propagate — if SPF Lookup shows an unexpected result right after a change, wait and re-check before assuming misconfiguration.
⭐
ToolsNovaHub Pro Tip
Run SPF Lookup from more than one network (office Wi-Fi + mobile data) to rule out local resolver caching before reporting a bug.
⚠️
Common Beginner Mistake
Editing a live DNS or mail record without noting the previous value first. Always save the old record from SPF Lookup's output so you can roll back instantly if something breaks.

📋 Related Tools & Guides Comparison

ResourceTypeLink
MX LookupToolOpen Tool →
DKIM LookupToolOpen Tool →
DMARC LookupToolOpen Tool →
Email CheckerToolOpen Tool →
SPF vs DKIM vs DMARC: How They Divide the WorkGuideRead Guide →

FAQ

SPF validates the sending IP. DKIM adds a cryptographic signature verified against a public key in DNS. DMARC ties both together, letting owners specify actions (none/quarantine/reject) when SPF or DKIM fails.
SPF pass means the sending IP matched an authorized mechanism. The email appears to come from an IP the domain owner approved — the desired outcome.
SPF fail (hardfail, -all) means the sending IP is not authorized. Depending on DMARC policy and the receiving server's configuration, the email may be rejected outright.
SPF softfail (~all) means the sending IP is not authorized, but the domain owner recommends accepting and marking as suspicious. Gmail typically delivers softfail email to spam.
redirect= replaces the entire SPF evaluation with another domain's SPF policy. Unlike include:, it must be the only mechanism and replaces all other mechanisms. Used when a third party manages your email policy entirely.
In your DNS panel, add a TXT record at @ (root domain) with value like: v=spf1 include:_spf.google.com -all. Replace the include with your email provider's SPF include. Changes take effect after TTL expires (typically 1 hour).
Run: dig TXT example.com +short | grep spf (Linux/Mac) or Resolve-DnsName example.com -Type TXT (Windows). This tool replicates that query in your browser with full parsing.
Yes — completely free, no sign-up needed, and we don't cap normal usage. Queries go through Google's public DNS-over-HTTPS resolver, which may itself rate-limit unusually heavy or automated traffic, but results otherwise appear instantly.