Email & SMTP
Check SPF Record
Find out whether your domain's SPF record is set up correctly and which servers it actually authorises.
The Problem
You don't know if your current SPF record is valid, whether it's missing a sending service (like your CRM or invoicing tool), or whether it's already over the 10-lookup limit that silently breaks SPF entirely.
About this problem
SPF records get messier over time as services are added and never removed — an old marketing tool here, a forgotten CRM there — until the record either silently exceeds the 10 DNS lookup limit (which makes SPF fail completely, not partially) or authorises a sender you don't even use any more.
This check is usually requested before making any changes, after a deliverability drop, or as part of a wider email health review, since most people have never actually looked at their raw SPF record since the day it was first set up.
What's Included
- Full lookup and parse of your current SPF record, if one exists
- Checking every include/redirect mechanism and counting DNS lookups against the 10-lookup limit
- Identifying missing or unauthorised senders
- A plain-English report of what the record currently allows and any problems found
What's NOT Included
- Actually changing or publishing the record (see "Fix SPF Record")
- Auditing your email content or spam score
- Testing other domains beyond the one you give me
How It Works
- Pull the current SPF TXT record directly from DNS, not from a dashboard that might cache an old value.
- Parse every include and redirect mechanism recursively, since each nested include costs a DNS lookup too.
- Count total DNS lookups against the hard 10-lookup RFC 7208 limit and flag if it's close to or over.
- Cross-reference every mechanism against services you've confirmed you actually use.
- Produce a plain-English breakdown: what's authorised, what's redundant, and what's missing.
In practice: you buy the service, send over whatever access or details the job needs, I investigate and do the work, and you confirm it's resolved before we call it done.
Frequently Asked Questions
- How do I check my SPF record manually?
- You can run a TXT lookup on your domain (e.g. with dig or an online SPF checker) and read the v=spf1 line, but correctly counting nested lookups and spotting what each include actually authorises takes more than a glance.
- What happens if my SPF record has too many DNS lookups?
- Past 10 lookups, SPF fails with a permerror for every mail check against that domain — mail servers are supposed to treat that as if there's no valid SPF at all, which can hurt deliverability across the board, not just for one sender.
- Can I have two SPF records?
- No — having more than one SPF TXT record is invalid and most mail servers will treat the whole thing as broken. All senders need to be combined into a single record.
- Why does my SPF record include services I don't recognise?
- Usually leftover from a tool you tried once, a developer who added it years ago, or a copy-pasted record from a guide — this check specifically flags anything that doesn't match services you've confirmed you use.
- Does checking my SPF record change anything?
- No, this is read-only — it tells you exactly what your current record does and any problems with it, without touching DNS. Fixing it is a separate, explicitly scoped service.
- How often should I check my SPF record?
- Any time you add or remove an email-sending tool, or if you notice a deliverability drop — there's no need for routine re-checks otherwise, since SPF doesn't change on its own.