Developer · Validator

SPF record syntax checker.

Paste an SPF TXT record, check it against the RFC 7208 grammar and count the terms that cost a DNS lookup. Runs in your browser; nothing is sent anywhere and no DNS lookup is made.

Advertisement

Input

This is the value of the TXT record published at your domain that starts with v=spf1. Surrounding quotes are fine. Paste several lines to check for duplicate SPF records.

Result

Paste a record and press Check.

What this checks, and what it cannot

The checker reads the text you paste, splits it into terms and tests each one against the grammar in RFC 7208 section 12. It makes no DNS query. Nested includes are not resolved, so an include: that itself contains more lookups is counted as one, and the true total can be higher than the number shown. It also cannot tell whether the record is published, or whether the domains it names exist.

Version: the record must start with v=spf1. A domain may publish only one such record; two give a permerror (section 4.5).

Qualifiers: + pass (the default when none is written), - fail, ~ softfail, ? neutral.

Mechanisms: all, include, a, mx, ptr, ip4, ip6, exists. Anything after all is ignored by receivers. ptr is marked “do not use” in section 5.5.

Modifiers: redirect= and exp=, each allowed once. Unknown modifiers are ignored. A redirect= is ignored when the record also has all.

The limit of 10: section 4.6.4 says the terms include, a, mx, ptr, exists and the redirect modifier each cost a DNS lookup, and evaluation must stop with a permerror if more than 10 are needed. all, ip4, ip6 and exp do not count. The same section says implementations SHOULD also limit “void lookups” (queries that return nothing) to two; that needs live DNS, so it is not checked here.

Checking the matching DMARC record too? Use the DMARC Record Validator.

Source: RFC 7208, section 12 (Collected ABNF) and section 4.6.4 (DNS Lookup Limits). Opened 2026-09-30.

Frequently asked questions

What is the SPF 10 lookup limit?

RFC 7208 section 4.6.4 requires receivers to stop at 10 DNS-querying terms while evaluating a record, counting include, a, mx, ptr, exists and redirect, including those reached through other domains’ records. Going over returns permerror, which usually means SPF fails for every message.

Why might my real lookup count be higher than this tool shows?

Each include: is one lookup here, but the included record may contain its own includes, a or mx terms, and those count too. This tool does not fetch them. Look up each included domain’s record and paste it in to count it separately.

Is +all really a problem?

It tells receivers every sender is authorized, so the record stops protecting the domain. A bare all means the same thing because the default qualifier is +. Most domains use -all or ~all.

Does a valid result mean SPF works for my domain?

No. It only means the pasted text follows the RFC 7208 grammar and stays within the lookup limit as far as it can be counted here. It does not confirm the record is published, the included domains resolve, or that your sending servers are covered.

Syntax check only

This tool checks the text you paste against RFC 7208 and counts lookup terms. It does not query DNS, does not resolve nested includes or redirects, and cannot confirm how any mail receiver will treat the record.

Advertisement
Advertisement
Listening…