See exactly which SPF records your domain publishes and whether they comply with RFC 7208. One record, valid syntax, and 10 or fewer DNS lookups across the full include tree: all three checks graded instantly, free and no signup needed.
A broken SPF record rarely announces itself. Mail drifts into spam, spoofed messages pass as you, and the only evidence sits in a header nobody opens. A lookup shows exactly what the internet resolves.
The lookup reads your live DNS exactly the way a receiving mail server does, then grades what it finds against the RFC 7208 rules behind permerrors.
We query DNS for TXT records at the domain and keep every one that starts with v=spf1.
Every include and redirect is resolved from DNS, each domain shown with the lookups it burns and any resolution errors.
Three checks grade the setup: exactly one record, parseable syntax, and no more than 10 DNS lookups across the entire tree. Anything red needs fixing.
What an SPF lookup checks, why the 10-lookup limit matters, and what to fix when a domain fails compliance.
The tool fetches every TXT record starting with v=spf1 published at your domain, resolves the include tree from DNS, and grades the setup against three RFC 7208 compliance checks: exactly one record, syntactically valid content, and 10 or fewer DNS-querying mechanisms across the whole tree. You see the records verbatim, the full include tree, and a pass or fail verdict for each check.
SPF lookup shows you the state of things: the records your domain publishes, the resolved include tree, and its total DNS-lookup cost. SPF flattening fixes an oversized record by collecting every IP in the tree and serving them from Maileroo-managed DNS, so you publish one short record that never creeps over the limit. Run a lookup first, then flatten if the lookup count fails.
RFC 7208 section 3.2 allows a domain at most one v=spf1 record. Two or more cause a permanent error (permerror), so receivers ignore every record and your SPF policy stops working entirely. Merge all sending sources into a single record instead of publishing a second one.
RFC 7208 caps an SPF evaluation at 10 DNS-querying mechanisms, counting include, a, mx, ptr, exists, and redirect. Past the limit the check returns permerror, which many receivers treat as an authentication failure. Nested includes from large providers push records over the limit faster than most people expect.
Your domain publishes no v=spf1 TXT record, so receivers have no list of authorized senders to check against. Anyone can spoof the domain and nothing will stop them at the SPF layer. Publish a single record, even a minimal v=spf1 -all, to close the gap.
Yes, free with no signup required. Run a lookup whenever your DNS changes, then use the SPF Record Generator to build a compliant record or the SPF Flattening tool to repair an oversized one.
Everything behind reliable delivery at any volume: sending, verification, routing, and the analytics to see what happened, from first API call to millions a month.
Send transactional and bulk emails through reliable SMTP infrastructure built for speed, security, and deliverability.
Integrate email delivery into your applications using powerful APIs built for flexibility, scalability, and performance.
Separate transactional and marketing traffic into isolated sending streams to protect reputation and keep critical emails fast.
Receive and route incoming emails directly into your applications using flexible automation and processing workflows.
Create and deliver marketing campaigns designed to increase engagement, reach, and customer retention.
Receive real-time event notifications for deliveries, opens, and clicks for storage and automation workflows.
Monitor email performance with detailed insights, reporting tools, and actionable delivery metrics in real time.
Gain greater sending control with dedicated IPs designed for consistency, reputation, scalability, and reliability.
Build integrations faster using SDKs, code examples, and resources for modern application development.