Check your SPF record and see exactly how to fix it.

We read your SPF record, count its DNS lookups against the limit of 10, and explain every part of it in plain English. Your DKIM, DMARC, MX and blacklist results come with it.

Works with a domain or a full email address. We read DNS fresh on every run.

Example report for trynorthpeak.example, a made-up new cold email domain

3 of 5 checks pass. Fix SPF first: until SPF passes, this domain falls short of the rules Gmail, Yahoo and Outlook set for bulk senders.

Receivers read exactly one SPF record. When they find more, they stop and return a permanent error (RFC 7208), which counts as no SPF at all.

What we found
v=spf1 include:_spf.google.com ~all
v=spf1 include:secureserver.net -all
How to fix it

Delete both records and publish this one in their place. Your mail is handled by Google Workspace, so include:secureserver.net, GoDaddy's email service, is left out. Add it back only if you also send mail that way.

v=spf1 include:_spf.google.com ~all

Add it as a TXT record with host @ in your DNS, in place of any SPF record already there. This record uses 1 of the 10 DNS lookups SPF allows.

Lookup tree after the fix: 1 of 10 DNS lookups
·trynorthpeak.example v=spf1 include:_spf.google.com ~all
1include:_spf.google.com v=spf1 ip4:74.125.0.0/16 ip4:209.85.128.0/17 ip6:2001:4860:4864::/56 ip6:2404:6800:4864::/56 ip6:2607:f8b0:4864::/56 ip6:2800:3f0:4864::/56 ip6:2a0...
Every part of the fixed record, in plain English
include:_spf.google.comGoogle Workspace may send for this domain. Costs 1 lookup.
~allMail from any other server is marked as suspicious (soft fail). Use -all to have it fail outright.
Also checked for trynorthpeak.example

We can set up your next sending domains with all five checks already passing.

We register the domains, create Google Workspace mailboxes with SPF, DKIM and DMARC in place, and connect them to Emailchaser with warm-up switched on. $6 a mailbox a month, plus $3 setup per mailbox and the domain ($16.59 a year for a .com). Ready in 24 to 48 hours.

The check runs on our server against live DNS and 16 public blocklists (3 for domains, 13 for mail server IPs). A list that does not answer is never counted as clean. Nothing you type is stored.

An SPF record breaks at 11 DNS lookups, even when every line in it is correct.

Each include, a, mx, ptr and exists term makes the receiving server do another DNS lookup, and so do the includes inside those includes. RFC 7208 caps the total at 10. One lookup over, and the whole record returns a permanent error, which Gmail treats as no SPF at all. The tree in the report above counts every lookup for you, nested ones included, and shows which include costs the most.

That is why an SPF record grows until it breaks. Each new tool someone in the company signs up for asks you to add its include: a help desk, a CRM, a newsletter tool, a billing system. Each one looks harmless on its own. The fifth or sixth one pushes the count past 10, and from that moment every message from the domain fails SPF, including the ones from Google Workspace that worked yesterday.

ip4 and ip6 terms cost nothing, because the address is already in the record. That is what "flattening" an SPF record means: replacing includes with the addresses they resolve to. It works until the provider changes its addresses, which is why we suggest removing includes you no longer use before you flatten anything.

Every part of an SPF record has one job.

TermWhat it meansDNS lookups
v=spf1Marks the TXT record as SPF. It must come first.0
include:_spf.google.comEvery server the other domain's SPF record allows may send for you.1, plus the lookups inside it
aThe server at your domain's own address (its A record) may send.1
mxYour own mail servers (your MX records) may send.1
ip4:203.0.113.0/24Servers in this address range may send.0
ip6:2001:db8::/32The same for IPv6 addresses.0
exists:%{i}.spf.examplePasses when a name built from the message resolves. Rare outside large providers.1
ptrMatches on reverse DNS. RFC 7208 says not to use it.1
redirect=_spf.example.comUse another domain's record in place of this one. Only read when there is no all term.1
~all / -allWhat happens to every server not listed: soft fail or fail.0

A sign in front of a term changes what a match means: + pass (the default), - fail, ~ soft fail and ? neutral. In practice only the all term at the end carries one. A record that ends in +all or plain all passes every server on the internet, and our check fails it.

Some providers' includes cost one lookup, and some cost seven.

We ran each provider's documented include through the checker on its own. The number is the include plus every lookup nested inside it, which is what it costs you out of 10.

ProviderIncludeLookups it costs
Google Workspaceinclude:_spf.google.com1
Microsoft 365include:spf.protection.outlook.com1
Amazon SESinclude:amazonses.com1
Postmarkinclude:spf.mtasv.net1
Brevoinclude:spf.brevo.com1
Zendeskinclude:mail.zendesk.com1
Fastmailinclude:spf.messagingengine.com1
Mailchimpinclude:servers.mcsv.net1
SendGridinclude:sendgrid.net2
Zoho Mailinclude:zohomail.com2
Salesforceinclude:_spf.salesforce.com2
Proton Mailinclude:_spf.protonmail.ch2
GoDaddy emailinclude:secureserver.net3
Mailguninclude:mailgun.org5
Freshdeskinclude:email.freshdesk.com7

Measured on live DNS on 6 October 2026. Providers change their records without notice, so check your own record above rather than adding these up.

Google Workspace and Microsoft 365 cost one lookup each, so a domain that only sends through one of them has nine to spare. The expensive ones are the services that nest includes for several mail systems of their own.

Two SPF records on one domain is the most common way to break SPF.

It usually happens when a domain changes hands between services. The registrar publishes a default record for its own email service, then someone adds Google Workspace's record next to it instead of replacing it. Both look valid on their own, and together they fail: receivers read exactly one SPF record, and when they find two they return a permanent error for every message.

When our check finds more than one, it writes the merged record for you: one v=spf1, every include and address from the old records once, and one all term. If your mail runs on a provider we recognise and one of the old records is a registrar's default include (GoDaddy's secureserver.net, for example), the merged record leaves it out and says so. The report also counts the merged record's lookups before you publish it.

You publish an SPF record as one TXT record at the root of the domain.

  1. Open the DNS settings wherever your domain's nameservers are: the registrar, Cloudflare or your host.
  2. Find any TXT record whose value starts with v=spf1. If there is one, edit it. Do not add a second.
  3. Use the host @ (some panels want the domain name itself, or leave the host empty). For a subdomain such as mail.yourdomain.com, the host is mail.
  4. Paste the record from the report, save, and run the check again once the TTL has passed.

A domain that never sends email should still publish v=spf1 -all, which tells receivers to fail any message that claims to come from it. Gmail, Yahoo and Outlook all list SPF among their requirements for bulk senders: Google, Yahoo and Microsoft (read 6 October 2026).

Most broken SPF records fail for one of five reasons.

Every one of these returns a permanent error or lets the wrong servers through, and every one is easy to miss by reading the record by eye, because each term on its own looks fine.

What we findWhat receivers doThe fix
Two or more SPF recordsReturn a permanent error, so SPF fails for every messageMerge them into one record; the report writes it for you
More than 10 DNS lookupsReturn a permanent error once the count passes 10Remove includes you no longer use, then flatten the rest if you must
An include with no SPF record behind itReturn a permanent error when they reach itFix the spelling or remove the include
+allPass mail from every server on the internetEnd the record with ~all or -all
No all term at the endTreat unlisted servers as neutral, neither pass nor failAdd ~all or -all as the last term

A sixth problem is quieter: a record longer than 255 characters pasted as one string. DNS stores TXT values in chunks of up to 255 characters, and most DNS panels split a long record for you. If yours does not, it may cut the record off, and the check above will show the record exactly as receivers read it.

SPF passing is not the same as DMARC passing.

SPF checks the domain in the return-path address, the one bounces go to, not the one your recipient sees in From. When you send through a service that uses its own return-path, SPF can pass for that service's domain while doing nothing for yours. DMARC only counts SPF when the two domains match, which is called alignment.

That is why the other four checks run with this one. DKIM signs with your own domain and survives forwarding, so it is the record DMARC leans on most. See your DKIM key on the DKIM checker and your policy on the DMARC checker, or build a new SPF record from scratch with the SPF record generator.

Common questions about SPF records

What is an SPF record?

A TXT record at the root of your domain that lists the servers allowed to send email as your domain. A receiving server looks it up for every message and checks whether the server that delivered it is on the list.

How many SPF records can a domain have?

Exactly one. With two or more, receivers stop and return a permanent error (RFC 7208), which counts as no SPF at all. Merge them into one record that keeps every include you still use.

What is the SPF 10 lookup limit?

Every include, a, mx, ptr and exists term makes the receiving server do a DNS lookup, and so do the terms inside each include. RFC 7208 caps the total at 10. One more and the whole record returns a permanent error. Our checker counts every nested lookup and shows the tree.

Should I use ~all or -all?

Either is fine for cold email. ~all (soft fail) marks mail from unlisted servers as suspicious, -all (hard fail) says it should fail. Gmail, Yahoo and Outlook ask for SPF to pass, not for one ending over the other. Never use +all, which lets anyone send as you.

Does SPF alone stop my emails going to spam?

No. Gmail, Yahoo and Outlook also want DKIM and a DMARC record from anyone sending in bulk, and DMARC needs SPF or DKIM to pass for the same domain as your From address. The check above runs all five.

What is an SPF PermError?

A permanent error: the receiver could not evaluate your record at all, so SPF counts as failed for every message. The usual causes are two SPF records, more than 10 DNS lookups, an include that points at a name with no SPF record, or a typo in a term. Our check names which one it found.

Does a subdomain need its own SPF record?

Yes, if it sends mail. SPF is not inherited: mail.yourdomain.com is checked against its own TXT record, not the root domain's. A subdomain that never sends can publish v=spf1 -all.

How long does an SPF change take to show up?

As long as the TTL on the old record, often between 5 minutes and an hour. Our check reads DNS fresh on every run, so run it again after the change.

More free tools for your sending setup

Send cold email from domains that pass all five checks.

Every plan includes warm-up, follow-ups and unlimited email accounts, from $47 a month.

Start my free trial7-day free trial, $0 today