Your list of allowed senders, and what its last word does.
The SPF record is the list of servers allowed to send as your domain. The checker reads it from public DNS, counts its lookups against the limit of ten and says what becomes of any sender missing from it.
Checking
Reading your domain
Your result
The record is on this page. Publishing it is yours to do, or ours.
Copy the record shown above and follow the numbered steps further down. Most domains take one sitting at the DNS host.
Go to the stepsWe publish SPF, DKIM and DMARC for the domain and verify each one once it is live. Report reading, the later move to reject and support after that are separate work.
Ask us in writingYou receive the scope and the price in writing before any record is touched.
The record, its ending and its lookup count.
The count is the number nobody checks until their own mail begins to fail. The other records are read in the same pass, because SPF alone rarely stops a forgery.
The record as published
The exact text at your domain, shown so you can compare it with what your DNS host displays.
The ending
-all refuses, ~all marks and delivers, ?all takes no view, +all lets anyone send as you.
Lookups used
Every include:, a, mx and redirect counts against ten, nested includes too.
More than one record
Two SPF records count as an error, and receivers may apply neither. There should be exactly one.
DKIM
Whether your mail is signed. SPF is one of three signals, and spam filtering weighs all of them.
DMARC
Whether anything tells receivers to act on an SPF failure. Without it, a perfect list stops little.
MX
Who runs your mail, which is the clue to the include line your record needs.
The verdict
One sentence on what a sender outside your list can do today.
Build the list first, tighten it last.
Publishing takes minutes. Knowing every service that belongs on the list is the work, and getting the order of the two wrong is how working mail gets cut off.
Change this today, if your record ends +all
+all authorises anyone to send as you, which is worse than having no record. Changing it to ~all is the one SPF edit that is safe without any evidence.
One record per domain
If a record already exists, edit it and add the new include to it. A second SPF record is treated as an error.
Read the MX line
The server name in your result tells you who runs your email.
Find their include
Search the provider’s help pages for their SPF include: line; every customer uses the same one.
List every other sender
Accounting or invoicing software, the booking system, a CRM, the website’s contact form, any newsletter tool.
Write one record
Join them and end with ~all: v=spf1 include:mail.example include:invoices.example ~all.
Publish at @
A TXT record with the Name blank or set to @.
Check again
The record should appear here with fewer than ten lookups.
Over ten lookups?
An include can hide further includes inside it, so four lines may add up to twelve lookups. Removing services you no longer use is usually enough to get back under the limit.
Leave ~all in place for now
Publish DMARC and read a few weeks of reports before moving to -all. Those reports name each server that sends in your name, the forgotten ones among them.
The order: read the record, fix only a reckless +all, find your real senders through DMARC reports, then tighten.
Rather not edit DNS yourself? We publish SPF, DKIM and DMARC for the domain and verify them, with the scope and the price in writing first. Ask us in writing.
Tightened too early, the record stops your own invoices.
The most common SPF failure has one cause: a service that sends as you was missing when the record went strict. A refused message does not bounce back; the tool reports it as sent and the customer never sees it. That is why we never hand out a strict record.
Your mail provider
Almost always on the list already.
Invoicing or accounting software
The sender most often forgotten.
The website contact form
Sends from the web host, which is rarely listed.
An old newsletter tool
Signed up for years ago; nobody on the team remembers it.
When we checked our own fourteen domains, eleven had no DMARC policy. Our own SPF still ends ~all, because our reports are not finished yet, and moving to -all before then would be the mistake described above.
A correct list with a soft ending enforces nothing.
Most businesses we check list their senders correctly, then end the record with an instruction to let everyone else through.
What ~all tells a receiver
This sender is not on my list; deliver it anyway and mark it as suspicious. For a forger, that is enough.
Soft is the right start
Starting soft is correct. The mistake is never coming back to tighten once the reports have shown every real sender.
A guest list, and the instruction to the doorman.
SPF names the servers allowed to send for your domain. The last word of the record tells the receiving server what to do with anyone not named.
-all
Refuse anyone not on the list. Safe only once every real sender is on it.
~all
Mark them as suspicious and deliver anyway. The right place to start.
?all
Take no view, which amounts to having no rule.
+all
Let anyone send as you. Change it today.
Four rules the checker keeps.
The checker only looks. Every change is one you make, at your own DNS host, when it suits you.
Always: public DNS, and nothing else
Every answer comes from records any mail server can look up. Nothing is sent to the domain and nothing about it is kept.
Always: the record as published, and a command to check it
Each line shows the raw text we read, with a dig command that returns the same answer on your own machine.
Never: your mailbox, your password or your DNS login
The check needs a domain name and nothing more. No test message is sent to or from the domain.
Never: a strict SPF record we cannot verify
Senders we cannot see from outside would be refused by it. When a record cannot be read, the result says unread, never missing.
Before you check your SPF.
Send any other question in writing; a written answer follows within one business day.
How do ~all and -all differ?
Both cover senders missing from your list. ~all is a soft fail: the message is marked and delivered. -all is a hard fail: it is refused. Only -all stops anything, and it is safe only once every service that sends as you is listed.
Why does the lookup count matter?
SPF allows ten DNS lookups. Each include:, a, mx and redirect uses one, and includes can contain more. Past ten, a receiver is entitled to stop reading the record partway, and genuine mail from you can begin to fail with nothing to say why.
Does SPF alone stop someone forging our address?
Rarely. SPF says who may send; DMARC tells receivers to act when a message fails. A flawless SPF record without DMARC still leaves the domain open to forgery, which is the pattern we meet most often.
Check another domain.
Read the SPF record of a second domain, or of a supplier you are about to pay. The count and the ending come back in about a second.