SPF TXT discovery
Finds v=spf1 records on your sending domain and flags missing or duplicate SPF entries.
Free tools
Enter the domain you send mail from to validate SPF TXT records, authorized mechanisms, syntax issues, and the 10-lookup limit before configuring providers in MailFleet.
Query TXT records, parse mechanisms, and count DNS lookups. Captcha required.
Capabilities
Catch duplicate records, lookup overflows, and weak all policies before they break authentication in production.
Finds v=spf1 records on your sending domain and flags missing or duplicate SPF entries.
Lists include, ip4, ip6, mx, a, and all mechanisms with qualifier policy (pass, fail, softfail).
Counts DNS lookups from nested include chains — exceeding 10 causes PermError and SPF failure.
Detects +all, missing all, deprecated ptr, and multiple SPF records.
Shows MX hosts and A records for the domain to help verify mx and a mechanisms.
Image captcha, session verification, and per-IP rate limits for public use.
How to use
Use the domain in your From address (e.g. yourdomain.com), not your website unless they match.
Complete the image challenge before running the DNS check.
Confirm a single v=spf1 TXT record and read the parsed mechanisms.
Ensure nested includes stay at or below 10 DNS lookups.
Update DNS, wait for propagation, then run the check again.
Sender Policy Framework (SPF) is a DNS TXT record that lists which mail servers may send email for your domain. Receiving servers compare the connecting IP against your SPF policy during authentication.
SPF is defined in RFC 7208. It works alongside DKIM and DMARC — SPF alone does not guarantee inbox placement, but missing or broken SPF hurts alignment and trust.
Each include:, a, mx, exists, and ptr mechanism can trigger DNS lookups. Nested include records add to the total. More than 10 lookups causes PermError — SPF fails entirely.
High lookup counts often come from multiple ESP includes. Consolidate providers, remove unused includes, or use SPF flattening when you approach the limit.
This checker validates DNS publication and SPF structure. It does not send test email or verify that your MailFleet provider IP is authorized — compare ip4 and include targets to your provider documentation.
DNS propagation can take minutes to 48 hours after changes. Re-test after TTL expires if results look stale.
For regulatory context on commercial email in the United States, see the FTC CAN-SPAM compliance guide.
Delivery note: MailFleet helps users manage campaigns through their own sending providers. Delivery outcomes depend on sender reputation, DNS authentication, content quality, recipient engagement, list quality, provider rules, and mailbox filtering systems.
RFC 7208 allows a maximum of 10 DNS lookups. Exceeding this causes PermError and SPF authentication failure.
Get started
MailFleet helps you configure providers and validate authentication before campaigns go out.
Available on
Same desktop experience across every platform — one workflow for your entire team.