Recursive policy evidence · read-only DNS

Free SPF checker and lookup explainer.

Find your published SPF policy, trace static includes and redirects, and understand visible DNS lookup pressure. The result explains evidence and limits without pretending to test inbox placement.

Check an SPF record

Inspect a sending domain

See the policy receivers can discover.

Enter the domain after @ in a business email address. We query its public TXT records and bounded static include or redirect targets.

Use a public domain or complete business email address—not a server IP or mailbox password.

Public DNS check. We read the SPF records published for this domain and follow a limited set of visible includes. Nothing is changed.

Read the count correctly

Policy inspection is not message authentication.

Potential path, not an exact run

SPF evaluation is left-to-right for a specific sending IP and identity. This tool statically expands visible policy dependencies, so actual receiver lookups can differ.

No inbox guarantee

A coherent SPF policy cannot guarantee delivery or placement. It does not test DKIM, DMARC alignment, reputation, message content or a receiving system.

Change DNS carefully

Do not replace a live record until every legitimate sender is inventoried. Removing a required provider can cause valid mail to fail SPF.

Standards-based explanation

The mechanism and lookup-limit wording follows the SPF specification.

Read RFC 7208

SPF questions

What this public check can establish.

What is the SPF 10 DNS lookup limit?

RFC 7208 limits the SPF terms that cause DNS queries during one evaluation. This checker shows potential pressure across the currently visible static expansion; the exact path depends on the sending IP and receiver evaluation.

Why can nested includes cause a problem?

Each include can contain further DNS-querying mechanisms. Provider changes can therefore consume lookup capacity even when your top-level record has not changed.

Does a valid SPF record guarantee email delivery?

No. SPF checks whether an SMTP identity authorises a sending host. Delivery and inbox placement depend on additional authentication, alignment, reputation, message and recipient-system factors.

Can this tool change or repair my record?

No. It performs read-only public DNS queries. Verify every legitimate sender and use appropriate technical review before changing production DNS.