Inspect your published SPF record and nested DNS lookups. Review missing records, duplicate records and lookup-limit warnings. No email or signup required.
It reads public DNS, follows nested includes and redirects within a bounded static check, and reports common configuration issues. It does not evaluate a specific message or sending IP.
The limit covers evaluated include, a, mx, ptr, exists, and redirect terms, including nested terms. An umbrella include still counts its children. A static expansion warning needs a message-specific check.
Both are valid. They produce softfail and fail respectively for unlisted senders. Confirm all legitimate sending services and follow their current setup instructions before changing the policy.
No. A domain lookup cannot show how a receiver evaluated an individual message. Inspect its authentication results and sending path when troubleshooting delivery.
Reviewed 22 September 2026. Sources: RFC 7208: SPF evaluation and limits
The full audit adds TLS, reverse DNS and IP blocklist checks.
Run the full free audit