Skip to main content
QUIETLYTIC
Email Security

SPF Checker

Look up a domain’s SPF record or paste one, and see every mechanism explained and counted.

Local · nothing leaves this browser Waiting for input
Esc Clear
Analysis

Paste an SPF record on the left.

How it works

An SPF record names which hosts may send mail using your domain in the envelope. It is a single line of terms evaluated left to right, and the first one that matches decides the result. Everything after it is dead text.

Two ways to check: paste a record, or look up a domain

RFC 7208 §4.6.4 allows ten DNS-querying mechanisms across a whole evaluation, and exceeding it is a permanent error rather than a soft warning — a permerror means SPF does not pass for legitimate mail. A pasted record is analysed in your browser with no DNS queries, so every include: counts as one and whatever that record itself declares is not counted at all: the number is a floor. Choose Look up a domain and Quietlytic fetches the published record through Cloudflare's DNS-over-HTTPS resolver, then follows each include: and redirect= and adds up what they declare. That is the total a receiver actually spends, and the include chain is listed so you can see which provider is using the budget.

Domain lookups need a one-time bot check, the same one the DNS Lookup uses, and are limited per hour. The MX Lookup shows where the same domain receives mail.

Qualifiers are the whole policy

-all rejects unlisted senders. ~all marks them suspicious. ?all asserts nothing, which is what receivers do anyway with no record at all. And +all, which is also what a bare all means, declares every host on the internet a legitimate sender — strictly worse than publishing nothing, because it converts silence into an explicit pass.

What an SPF pass does not tell you

SPF checks the envelope sender, which the recipient never sees. The visible From header is unrelated, and a message can pass SPF on an attacker-controlled domain while displaying yours. Closing that gap is what DMARC alignment is for — see the DMARC Record Analyzer.

Example

Look up a domain that sends through two providers and the chain shows each provider's record beneath your own, with its own lookup count. A record that declares three lookups can reach nine once both providers' includes are counted, which is why the lookup mode exists.

v=spf1 -all is a complete, valid record meaning "this domain sends no mail" — the correct record for a parked domain. v=spf1 mx a ptr ~all declares three lookups and one deprecated mechanism, and the ptr is ignored outright by some receivers.

Frequently asked questions

Why can the pasted count and the domain count differ?

Because each include: brings its own mechanisms into the same budget of ten. A pasted record can only be counted as written, so every include: counts as one. Looking up the domain follows each include: and adds what its record declares, which is the total a receiver actually spends.

What happens when an SPF record exceeds ten lookups?

RFC 7208 §4.6.4 makes it a permerror. A permerror is not a pass, so under DMARC legitimate mail fails SPF — the failure mode is silent delivery problems rather than an error anyone sees.

Is ~all or -all correct?

Both are valid. -all rejects unlisted senders outright; ~all marks them suspicious and is the normal setting while a sending inventory is still being confirmed. Under DMARC both fail SPF, so alignment is unaffected by the choice.

Why is a bare "all" treated as +all?

Because RFC 7208 defines + as the default qualifier. A record ending in a bare all authorises every host on the internet, which is the most damaging SPF mistake and the one that looks least like one.

Does pasting a record send it anywhere?

No. Parsing runs in your own tab and the page makes no network request. Only the "Look up domain" button sends anything: the domain name, to Quietlytic, which asks Cloudflare’s DNS resolver for the record.

Related tools

From the intelligence desk