ė.email

SPF · RFC 7208

SPF checker: the record, term by term, and its DNS lookups counted

Type a domain to read its SPF record. Every include and redirect is followed, and the lookups are counted against the limit of 10 that turns a working record into a permanent error.

The SPF checker

Try

The domain you type goes to two DNS-over-HTTPS operators, Google Public DNS and Cloudflare, straight from your browser, and to nobody else. It is not stored, and it is not put in this page's address. If you type an email address, only the part after the @ is used.

SPF

<domain> · TXT, v=spf1

Not checked yet

The SPF record term by term, every include and redirect followed, and the DNS lookups counted against the limit of 10.

What an SPF record is

SPF, the Sender Policy Framework, lets a domain declare which hosts are, and are not, authorized to use its name in the envelope of a message: the MAIL FROM address and the HELO name (RFC 7208 §3). The declaration is one TXT record, published at the domain itself and not under a subdomain, that begins with the version v=spf1.

v=spf1 +mx a:colo.example.com/28 -all

The example record of RFC 7208 §3: the domain's mail hosts pass, the 16 addresses around colo.example.com pass, every other server fails.

How to read an SPF record

After the version come the terms, separated by spaces. A receiver tests the mechanisms from left to right and stops at the first one that matches the connecting server; the sign in front of that mechanism is the result (RFC 7208 §4.6.2).

  • + pass, which is also what a mechanism with no sign means; - fail; ~ softfail, "a weak statement that the host is probably not authorized"; ? neutral (RFC 7208 §2.6).
  • ip4 and ip6 name an address or a network. a and mx name the addresses, or the mail hosts, of a domain. exists asks whether a constructed name has an address.
  • include runs the SPF check of another domain and matches if that check passes. It does not paste the other record into this one: a -all inside an included record does not end the outer evaluation (RFC 7208 §5.2).
  • all always matches, so it goes last. Mechanisms after it are never tested (RFC 7208 §5.1).
  • redirect= hands the whole decision to another domain's record when nothing matched. It is ignored if the record contains all (RFC 7208 §6.1).

SPF: too many DNS lookups

The terms include, a, mx, ptr, exists and redirect make the receiver ask the DNS. Receivers must limit the total to 10 during one evaluation, and return the permanent error "permerror" when the limit is exceeded; all, ip4, ip6 and exp cost nothing (RFC 7208 §4.6.4). The count includes every term of every record reached through an include or a redirect, which is why a record with three includes can need fifteen lookups.

Two smaller limits sit beside it. An mx term must not lead to address lookups for more than 10 mail hosts. And receivers should stop with a permanent error after two void lookups, queries that find no record or no such name (RFC 7208 §4.6.4).

The checker counts to the end of the record and of every record it includes. That is the most a receiver can be made to ask; a message from a server that matches early costs fewer. To bring a record under the limit, remove the includes of services that no longer send the domain's mail, and replace a and mx with the addresses themselves where they are stable. RFC 7208 calls a record made of ip4 terms the best one and mx an expensive one (RFC 7208 §10.1.1).

The common mistakes

  • Two SPF records. A second record is not added to the first. With more than one record that begins with v=spf1 the result is a permanent error (RFC 7208 §4.5).
  • Ending in +all. It authorizes every server on the internet.
  • No ending at all. Without all or redirect, servers that match nothing get "neutral", as if the record ended in ?all (RFC 7208 §4.7).
  • Terms after all. They are never reached.
  • Using ptr. The RFC says it should not be published: it is slow and less reliable than the other mechanisms (RFC 7208 §5.5).
  • An include that points at nothing. If the included domain has no SPF record, the include is a permanent error, not a harmless miss (RFC 7208 §5.2).
  • One long string. A single character-string in a TXT record holds 255 octets; a longer record is published as several strings, which receivers join with nothing between them (RFC 7208 §3.3).
  • A record of type SPF. The separate SPF record type was discontinued; SPF is published as TXT only (RFC 7208 §3.1).

What this checker does not tell you

It does not say whether a particular message passes SPF. That depends on the server that delivers the message and on the envelope sender, and there is no message here. It reads the published record, follows it, and counts. SPF alone also decides nothing about the From address a person sees: that is the job of DMARC, which uses the SPF result only when the domain SPF checked matches the domain in From.