SPF Checker
Validate your SPF record and see the whole include tree.
Related Tools
DMARC Checker
Check a domain's DMARC policy. Tags explained in plain English, reporting verified.
Use tool →DKIM Checker
Look up and validate DKIM records by selector. Key type, size, and testing flags.
Use tool →MX Record Lookup
Look up MX records for any domain. See mail servers, priorities, and misconfigurations.
Use tool →SPF, DKIM & DMARC Generator
Generate SPF, DKIM, and DMARC DNS records for Google Workspace, Microsoft 365, or custom setups.
Use tool →How to Check an SPF Record
Enter your domain and hit Check. The tool fetches your SPF record over DNS-over-HTTPS, straight from your browser, then follows every include and redirect it references. You get the full include tree, a running count against the 10-lookup limit, your effective policy, and a checklist of everything receivers would trip on.
The lookup counter is the part most SPF checkers get wrong or skip. We count every include, a, mx, ptr, exists, and redirect in the whole tree, the same way receivers budget them. If you're at 9 of 10, you'll know before the next marketing tool pushes you over.
How the 10-Lookup Limit Sneaks Up on You
Nobody writes an SPF record with 11 lookups on purpose. It accumulates. Google Workspace costs 1 to 3. Your email marketing platform adds one or two more. Then the CRM, the help desk, the billing system, the survey tool someone in ops signed up for in 2023. Each one says "just add include:spf.us.com to your record" and each one quietly spends your budget.
When you cross 10, nothing warns you. Mail keeps sending. But receivers evaluating your record hit the limit and return permerror, DMARC stops getting an SPF pass, and deliverability erodes until someone finally checks. The fix is pruning: drop includes for services you've stopped using, and check whether your ESP can sign with DKIM on a dedicated domain instead of piggybacking on your root SPF.
Reading Your Include Tree
The tree shows every domain your SPF record pulls in, nested the way receivers resolve them. The @N marker on each branch shows which lookup number that fetch was, so you can see exactly which include pushed you near the limit. Red badges mean a branch is broken: NXDOMAIN means the target domain doesn't exist, NO SPF RECORD means it exists but publishes nothing useful, and LOOP means a record includes itself somewhere down the chain. Any of those is a permerror waiting for a receiver to find it.
SPF is one third of email authentication. Check your DMARC policy with the DMARC Checker, verify your signing keys with the DKIM Checker, or build all three records with the SPF, DKIM & DMARC Generator.