SPF record checker
Look up a domain's SPF record, count its DNS lookups across every include, and find the mistakes that make receivers ignore it.
What this checks
That there's exactly one SPF record, that it stays within the limit of 10 DNS lookups once every include is followed, that each include actually has an SPF record, and how the record treats servers it doesn't list.
SPF and toSend
toSend's SPF record lives on a subdomain, send.yourdomain.com, which is also the bounce address on every email we send. You don't need to add toSend to your main domain's SPF record, so it won't use up any of your 10 lookups.
Questions
Why is there a limit of 10 lookups?
The SPF standard caps the number of DNS lookups a receiver will make while checking one record. Each include, a, mx, ptr, exists and redirect counts, including the ones inside included records. Above 10, the result is an error and SPF fails.
Should I use ~all or -all?
~all (soft fail) is the common choice and works well with DMARC. -all (fail) is stricter. Never use +all, which lets any server pass.
Can I have two SPF records?
No. A domain must have exactly one TXT record starting with v=spf1. With two, receivers treat SPF as broken. Merge them into one record.
Ready to send? Your first 10,000 are on us.
Every feature included. No tiers. For one website, one app, or fifty client sites.