Check your SPF record and see exactly how to fix it.
We read your SPF record, count its DNS lookups against the limit of 10, and explain every part of it in plain English. Your DKIM, DMARC, MX and blacklist results come with it.
Works with a domain or a full email address. We read DNS fresh on every run.
3 of 5 checks pass. Fix SPF first: until SPF passes, this domain falls short of the rules Gmail, Yahoo and Outlook set for bulk senders.
Receivers read exactly one SPF record. When they find more, they stop and return a permanent error (RFC 7208), which counts as no SPF at all.
v=spf1 include:_spf.google.com ~all v=spf1 include:secureserver.net -all
Delete both records and publish this one in their place. Your mail is handled by Google Workspace, so include:secureserver.net, GoDaddy's email service, is left out. Add it back only if you also send mail that way.
v=spf1 include:_spf.google.com ~all
Add it as a TXT record with host @ in your DNS, in place of any SPF record already there. This record uses 1 of the 10 DNS lookups SPF allows.
| include:_spf.google.com | Google Workspace may send for this domain. Costs 1 lookup. |
| ~all | Mail from any other server is marked as suspicious (soft fail). Use -all to have it fail outright. |
We can set up your next sending domains with all five checks already passing.
We register the domains, create Google Workspace mailboxes with SPF, DKIM and DMARC in place, and connect them to Emailchaser with warm-up switched on. $6 a mailbox a month, plus $3 setup per mailbox and the domain ($16.59 a year for a .com). Ready in 24 to 48 hours.
The check runs on our server against live DNS and 16 public blocklists (3 for domains, 13 for mail server IPs). A list that does not answer is never counted as clean. Nothing you type is stored.
An SPF record breaks at 11 DNS lookups, even when every line in it is correct.
Each include, a, mx, ptr and exists term makes the receiving server do another DNS lookup, and so do the includes inside those includes. RFC 7208 caps the total at 10. One lookup over, and the whole record returns a permanent error, which Gmail treats as no SPF at all. The tree in the report above counts every lookup for you, nested ones included, and shows which include costs the most.
That is why an SPF record grows until it breaks. Each new tool someone in the company signs up for asks you to add its include: a help desk, a CRM, a newsletter tool, a billing system. Each one looks harmless on its own. The fifth or sixth one pushes the count past 10, and from that moment every message from the domain fails SPF, including the ones from Google Workspace that worked yesterday.
ip4 and ip6 terms cost nothing, because the address is already in the record. That is what "flattening" an SPF record means: replacing includes with the addresses they resolve to. It works until the provider changes its addresses, which is why we suggest removing includes you no longer use before you flatten anything.
Every part of an SPF record has one job.
| Term | What it means | DNS lookups |
|---|---|---|
| v=spf1 | Marks the TXT record as SPF. It must come first. | 0 |
| include:_spf.google.com | Every server the other domain's SPF record allows may send for you. | 1, plus the lookups inside it |
| a | The server at your domain's own address (its A record) may send. | 1 |
| mx | Your own mail servers (your MX records) may send. | 1 |
| ip4:203.0.113.0/24 | Servers in this address range may send. | 0 |
| ip6:2001:db8::/32 | The same for IPv6 addresses. | 0 |
| exists:%{i}.spf.example | Passes when a name built from the message resolves. Rare outside large providers. | 1 |
| ptr | Matches on reverse DNS. RFC 7208 says not to use it. | 1 |
| redirect=_spf.example.com | Use another domain's record in place of this one. Only read when there is no all term. | 1 |
| ~all / -all | What happens to every server not listed: soft fail or fail. | 0 |
A sign in front of a term changes what a match means: + pass (the default), - fail, ~ soft fail and ? neutral. In practice only the all term at the end carries one. A record that ends in +all or plain all passes every server on the internet, and our check fails it.
Some providers' includes cost one lookup, and some cost seven.
We ran each provider's documented include through the checker on its own. The number is the include plus every lookup nested inside it, which is what it costs you out of 10.
| Provider | Include | Lookups it costs |
|---|---|---|
| Google Workspace | include:_spf.google.com | 1 |
| Microsoft 365 | include:spf.protection.outlook.com | 1 |
| Amazon SES | include:amazonses.com | 1 |
| Postmark | include:spf.mtasv.net | 1 |
| Brevo | include:spf.brevo.com | 1 |
| Zendesk | include:mail.zendesk.com | 1 |
| Fastmail | include:spf.messagingengine.com | 1 |
| Mailchimp | include:servers.mcsv.net | 1 |
| SendGrid | include:sendgrid.net | 2 |
| Zoho Mail | include:zohomail.com | 2 |
| Salesforce | include:_spf.salesforce.com | 2 |
| Proton Mail | include:_spf.protonmail.ch | 2 |
| GoDaddy email | include:secureserver.net | 3 |
| Mailgun | include:mailgun.org | 5 |
| Freshdesk | include:email.freshdesk.com | 7 |
Measured on live DNS on 6 October 2026. Providers change their records without notice, so check your own record above rather than adding these up.
Google Workspace and Microsoft 365 cost one lookup each, so a domain that only sends through one of them has nine to spare. The expensive ones are the services that nest includes for several mail systems of their own.
Two SPF records on one domain is the most common way to break SPF.
It usually happens when a domain changes hands between services. The registrar publishes a default record for its own email service, then someone adds Google Workspace's record next to it instead of replacing it. Both look valid on their own, and together they fail: receivers read exactly one SPF record, and when they find two they return a permanent error for every message.
When our check finds more than one, it writes the merged record for you: one v=spf1, every include and address from the old records once, and one all term. If your mail runs on a provider we recognise and one of the old records is a registrar's default include (GoDaddy's secureserver.net, for example), the merged record leaves it out and says so. The report also counts the merged record's lookups before you publish it.
You publish an SPF record as one TXT record at the root of the domain.
- Open the DNS settings wherever your domain's nameservers are: the registrar, Cloudflare or your host.
- Find any TXT record whose value starts with
v=spf1. If there is one, edit it. Do not add a second. - Use the host
@(some panels want the domain name itself, or leave the host empty). For a subdomain such asmail.yourdomain.com, the host ismail. - Paste the record from the report, save, and run the check again once the TTL has passed.
A domain that never sends email should still publish v=spf1 -all, which tells receivers to fail any message that claims to come from it. Gmail, Yahoo and Outlook all list SPF among their requirements for bulk senders: Google, Yahoo and Microsoft (read 6 October 2026).
Most broken SPF records fail for one of five reasons.
Every one of these returns a permanent error or lets the wrong servers through, and every one is easy to miss by reading the record by eye, because each term on its own looks fine.
| What we find | What receivers do | The fix |
|---|---|---|
| Two or more SPF records | Return a permanent error, so SPF fails for every message | Merge them into one record; the report writes it for you |
| More than 10 DNS lookups | Return a permanent error once the count passes 10 | Remove includes you no longer use, then flatten the rest if you must |
| An include with no SPF record behind it | Return a permanent error when they reach it | Fix the spelling or remove the include |
| +all | Pass mail from every server on the internet | End the record with ~all or -all |
| No all term at the end | Treat unlisted servers as neutral, neither pass nor fail | Add ~all or -all as the last term |
A sixth problem is quieter: a record longer than 255 characters pasted as one string. DNS stores TXT values in chunks of up to 255 characters, and most DNS panels split a long record for you. If yours does not, it may cut the record off, and the check above will show the record exactly as receivers read it.
SPF passing is not the same as DMARC passing.
SPF checks the domain in the return-path address, the one bounces go to, not the one your recipient sees in From. When you send through a service that uses its own return-path, SPF can pass for that service's domain while doing nothing for yours. DMARC only counts SPF when the two domains match, which is called alignment.
That is why the other four checks run with this one. DKIM signs with your own domain and survives forwarding, so it is the record DMARC leans on most. See your DKIM key on the DKIM checker and your policy on the DMARC checker, or build a new SPF record from scratch with the SPF record generator.
Common questions about SPF records
What is an SPF record?
A TXT record at the root of your domain that lists the servers allowed to send email as your domain. A receiving server looks it up for every message and checks whether the server that delivered it is on the list.
How many SPF records can a domain have?
Exactly one. With two or more, receivers stop and return a permanent error (RFC 7208), which counts as no SPF at all. Merge them into one record that keeps every include you still use.
What is the SPF 10 lookup limit?
Every include, a, mx, ptr and exists term makes the receiving server do a DNS lookup, and so do the terms inside each include. RFC 7208 caps the total at 10. One more and the whole record returns a permanent error. Our checker counts every nested lookup and shows the tree.
Should I use ~all or -all?
Either is fine for cold email. ~all (soft fail) marks mail from unlisted servers as suspicious, -all (hard fail) says it should fail. Gmail, Yahoo and Outlook ask for SPF to pass, not for one ending over the other. Never use +all, which lets anyone send as you.
Does SPF alone stop my emails going to spam?
No. Gmail, Yahoo and Outlook also want DKIM and a DMARC record from anyone sending in bulk, and DMARC needs SPF or DKIM to pass for the same domain as your From address. The check above runs all five.
What is an SPF PermError?
A permanent error: the receiver could not evaluate your record at all, so SPF counts as failed for every message. The usual causes are two SPF records, more than 10 DNS lookups, an include that points at a name with no SPF record, or a typo in a term. Our check names which one it found.
Does a subdomain need its own SPF record?
Yes, if it sends mail. SPF is not inherited: mail.yourdomain.com is checked against its own TXT record, not the root domain's. A subdomain that never sends can publish v=spf1 -all.
How long does an SPF change take to show up?
As long as the TTL on the old record, often between 5 minutes and an hour. Our check reads DNS fresh on every run, so run it again after the change.
More free tools for your sending setup
Send cold email from domains that pass all five checks.
Every plan includes warm-up, follow-ups and unlimited email accounts, from $47 a month.
Start my free trial7-day free trial, $0 today