SPF Checker

Your list of allowed senders, and what its last word does.

The SPF record is the list of servers allowed to send as your domain. The checker reads it from public DNS, counts its lookups against the limit of ten and says what becomes of any sender missing from it.

Public DNS only. No record handed over that we cannot verify.
brightwater.examplesample data
Record publishedyes
Senders allowed3
Lookups3 of 10
Anyone not listed~all, soft
The senders are right; the last word lets anyone else through.permissive
What it reads

The record, its ending and its lookup count.

The count is the number nobody checks until their own mail begins to fail. The other records are read in the same pass, because SPF alone rarely stops a forgery.

The record as published

The exact text at your domain, shown so you can compare it with what your DNS host displays.

The ending

-all refuses, ~all marks and delivers, ?all takes no view, +all lets anyone send as you.

Lookups used

Every include:, a, mx and redirect counts against ten, nested includes too.

More than one record

Two SPF records count as an error, and receivers may apply neither. There should be exactly one.

DKIM

Whether your mail is signed. SPF is one of three signals, and spam filtering weighs all of them.

DMARC

Whether anything tells receivers to act on an SPF failure. Without it, a perfect list stops little.

MX

Who runs your mail, which is the clue to the include line your record needs.

The verdict

One sentence on what a sender outside your list can do today.

The fix

Build the list first, tighten it last.

Publishing takes minutes. Knowing every service that belongs on the list is the work, and getting the order of the two wrong is how working mail gets cut off.

Change this today, if your record ends +all

+all authorises anyone to send as you, which is worse than having no record. Changing it to ~all is the one SPF edit that is safe without any evidence.

One record per domain

If a record already exists, edit it and add the new include to it. A second SPF record is treated as an error.

01MX line

Read the MX line

The server name in your result tells you who runs your email.

your provider
02provider

Find their include

Search the provider’s help pages for their SPF include: line; every customer uses the same one.

include:
03senders

List every other sender

Accounting or invoicing software, the booking system, a CRM, the website’s contact form, any newsletter tool.

every sender
04one record

Write one record

Join them and end with ~all: v=spf1 include:mail.example include:invoices.example ~all.

~all
05@

Publish at @

A TXT record with the Name blank or set to @.

TXT · @
06this page

Check again

The record should appear here with fewer than ten lookups.

under ten

Over ten lookups?

An include can hide further includes inside it, so four lines may add up to twelve lookups. Removing services you no longer use is usually enough to get back under the limit.

Leave ~all in place for now

Publish DMARC and read a few weeks of reports before moving to -all. Those reports name each server that sends in your name, the forgotten ones among them.

The order: read the record, fix only a reckless +all, find your real senders through DMARC reports, then tighten.

Rather not edit DNS yourself? We publish SPF, DKIM and DMARC for the domain and verify them, with the scope and the price in writing first. Ask us in writing.

What happens next

Tightened too early, the record stops your own invoices.

The most common SPF failure has one cause: a service that sends as you was missing when the record went strict. A refused message does not bounce back; the tool reports it as sent and the customer never sees it. That is why we never hand out a strict record.

01

Your mail provider

Almost always on the list already.

02

Invoicing or accounting software

The sender most often forgotten.

03

The website contact form

Sends from the web host, which is rarely listed.

04

An old newsletter tool

Signed up for years ago; nobody on the team remembers it.

When we checked our own fourteen domains, eleven had no DMARC policy. Our own SPF still ends ~all, because our reports are not finished yet, and moving to -all before then would be the mistake described above.

Why it matters

A correct list with a soft ending enforces nothing.

Most businesses we check list their senders correctly, then end the record with an instruction to let everyone else through.

What ~all tells a receiver

This sender is not on my list; deliver it anyway and mark it as suspicious. For a forger, that is enough.

Soft is the right start

Starting soft is correct. The mistake is never coming back to tighten once the reports have shown every real sender.

What SPF is

A guest list, and the instruction to the doorman.

SPF names the servers allowed to send for your domain. The last word of the record tells the receiving server what to do with anyone not named.

-all

Refuse anyone not on the list. Safe only once every real sender is on it.

~all

Mark them as suspicious and deliver anyway. The right place to start.

?all

Take no view, which amounts to having no rule.

+all

Let anyone send as you. Change it today.

We read, we never change

Four rules the checker keeps.

The checker only looks. Every change is one you make, at your own DNS host, when it suits you.

01

Always: public DNS, and nothing else

Every answer comes from records any mail server can look up. Nothing is sent to the domain and nothing about it is kept.

02

Always: the record as published, and a command to check it

Each line shows the raw text we read, with a dig command that returns the same answer on your own machine.

03

Never: your mailbox, your password or your DNS login

The check needs a domain name and nothing more. No test message is sent to or from the domain.

04

Never: a strict SPF record we cannot verify

Senders we cannot see from outside would be refused by it. When a record cannot be read, the result says unread, never missing.

FAQ

Before you check your SPF.

Send any other question in writing; a written answer follows within one business day.

How do ~all and -all differ?

Both cover senders missing from your list. ~all is a soft fail: the message is marked and delivered. -all is a hard fail: it is refused. Only -all stops anything, and it is safe only once every service that sends as you is listed.

Why does the lookup count matter?

SPF allows ten DNS lookups. Each include:, a, mx and redirect uses one, and includes can contain more. Past ten, a receiver is entitled to stop reading the record partway, and genuine mail from you can begin to fail with nothing to say why.

Does SPF alone stop someone forging our address?

Rarely. SPF says who may send; DMARC tells receivers to act when a message fails. A flawless SPF record without DMARC still leaves the domain open to forgery, which is the pattern we meet most often.

Start

Check another domain.

Read the SPF record of a second domain, or of a supplier you are about to pay. The count and the ending come back in about a second.