Skip to content
Public DNS · no signup · every include counted

SPF checker: count every lookup, not just the record.

An SPF check may make at most 10 DNS lookups (RFC 7208, section 4.6.4), and the lookups inside every include count toward that limit. Past 10, receivers return a permanent error and SPF fails for every message. This checker walks every include and redirect and counts the whole tree.

Reads the SPF record and every include over DNS-over-HTTPS. Works on any domain — the records are public.

01 — The limit people hit

Ten lookups, counted across the whole tree.

RFC 7208 allows an SPF evaluation ten terms that query DNS: include, a, mx, ptr, exists and redirect. The ones inside each include count too, so one line for a mail provider can cost three or four. Go past ten and receivers return a permanent error, which fails SPF for every message, including the legitimate ones.

The usual fix is to remove services you no longer send through, then check what is left. Build a replacement with the SPF record generator, or check the whole domain, DKIM and DMARC included, with the domain checker.

02 — FAQ

Frequently asked questions.

RFC 7208 allows one SPF evaluation at most 10 terms that cause a DNS query: include, a, mx, ptr, exists and redirect. Lookups inside each include count toward the same total. Past 10, receivers return a permanent error (permerror) and SPF fails for every message from the domain.

For the full walkthrough, see the SPF setup guide.

A passing record is not the same as aligned mail.

SPF only counts for DMARC when the authorized domain matches the From: address. Aggregate reports show, sender by sender, whether that happens. Monitor collects and reads them for 2 domains at no charge.

Free plan: 2 domains, no card, no expiry · Trial: card required, billed on day 15 unless you cancel · 14-day money-back on new paid plans