Big protection. Even on the free plan. Meet your new DNS home
KumoDNS
Free tool

SPF checker.

Expand a domain's SPF record in full — every include, what each term costs, and the two limits that break a record without telling you.

5 of 5 checks left this hour. (Psst — need more? Sign in now)

Two limits, and almost everybody only knows one

The ten-lookup limit is famous enough that most checkers count it. The second one is not: a lookup that returns nothing is a void lookup, and a record is allowed only two before a receiving server should return the same permanent error as going over ten.

So a record can sit comfortably at six lookups, pass every tool that counts to ten, and still fail — because three of the vendors in it shut down and nobody removed the includes. This page counts both, and marks every term that resolves to nothing.

What is the ten-lookup limit?

An SPF record may cost at most ten DNS lookups to evaluate. Every include, a, mx, ptr and exists costs one, and so does a redirect — counted recursively, so the lookups inside a record you include count against your ten as well. Go over and receiving servers return a permanent error, and most then treat your domain as having no SPF at all.

My record is under ten lookups and mail still fails SPF. Why?

The most likely answer is void lookups, which is the limit nobody checks. A lookup that returns nothing — a vendor who has shut down, a name with a typo in it — is a void lookup, and a record is allowed only two of them before a receiver should return the same permanent error. A record can sit at six lookups, look fine in every tool that counts to ten, and fail on this instead.

Why did my record break when I changed nothing?

Because the limit counts through includes, and most of yours belong to other companies. When a provider you include adds an address range or another include to their own record, your total goes up. Nothing tells you, there is no error anywhere you would see it, and the first symptom is mail being filed as spam.

How do I get back under the limit?

Remove sending services you no longer use, which is usually most of the problem. Replace an include with the ip4 and ip6 ranges it resolves to if the provider publishes stable addresses, since literal ranges cost nothing. Drop any ptr term. And check the tree on this page for the same name reached twice by different routes — each occurrence is charged separately.

Fix it where you host the zone

Every change published to our nameservers in seconds, with a full history of what changed and a recycle bin for the days it goes wrong. Every zone is DDoS-protected, on every plan including the free one.

Top