SPF
<domain> · TXT, v=spf1
Not checked yetThe SPF record term by term, every include and redirect followed, and the DNS lookups counted against the limit of 10.
SPF · RFC 7208
Type a domain to read its SPF record. Every include and redirect is followed, and the lookups are counted against the limit of 10 that turns a working record into a permanent error.
<domain> · TXT, v=spf1
Not checked yetThe SPF record term by term, every include and redirect followed, and the DNS lookups counted against the limit of 10.
SPF, the Sender Policy Framework, lets a domain declare which hosts are, and are not, authorized to use its name in the envelope of a message: the MAIL FROM address and the HELO name (RFC 7208 §3). The declaration is one TXT record, published at the domain itself and not under a subdomain, that begins with the version v=spf1.
v=spf1 +mx a:colo.example.com/28 -all
The example record of RFC 7208 §3: the domain's mail hosts pass, the 16 addresses around colo.example.com pass, every other server fails.
After the version come the terms, separated by spaces. A receiver tests the mechanisms from left to right and stops at the first one that matches the connecting server; the sign in front of that mechanism is the result (RFC 7208 §4.6.2).
+ pass, which is also what a mechanism with no sign means; - fail; ~ softfail, "a weak statement that the host is probably not authorized"; ? neutral (RFC 7208 §2.6).ip4 and ip6 name an address or a network. a and mx name the addresses, or the mail hosts, of a domain. exists asks whether a constructed name has an address.include runs the SPF check of another domain and matches if that check passes. It does not paste the other record into this one: a -all inside an included record does not end the outer evaluation (RFC 7208 §5.2).all always matches, so it goes last. Mechanisms after it are never tested (RFC 7208 §5.1).redirect= hands the whole decision to another domain's record when nothing matched. It is ignored if the record contains all (RFC 7208 §6.1).The terms include, a, mx, ptr, exists and redirect make the receiver ask the DNS. Receivers must limit the total to 10 during one evaluation, and return the permanent error "permerror" when the limit is exceeded; all, ip4, ip6 and exp cost nothing (RFC 7208 §4.6.4). The count includes every term of every record reached through an include or a redirect, which is why a record with three includes can need fifteen lookups.
Two smaller limits sit beside it. An mx term must not lead to address lookups for more than 10 mail hosts. And receivers should stop with a permanent error after two void lookups, queries that find no record or no such name (RFC 7208 §4.6.4).
The checker counts to the end of the record and of every record it includes. That is the most a receiver can be made to ask; a message from a server that matches early costs fewer. To bring a record under the limit, remove the includes of services that no longer send the domain's mail, and replace a and mx with the addresses themselves where they are stable. RFC 7208 calls a record made of ip4 terms the best one and mx an expensive one (RFC 7208 §10.1.1).
v=spf1 the result is a permanent error (RFC 7208 §4.5).+all. It authorizes every server on the internet.all or redirect, servers that match nothing get "neutral", as if the record ended in ?all (RFC 7208 §4.7).all. They are never reached.ptr. The RFC says it should not be published: it is slow and less reliable than the other mechanisms (RFC 7208 §5.5).It does not say whether a particular message passes SPF. That depends on the server that delivers the message and on the envelope sender, and there is no message here. It reads the published record, follows it, and counts. SPF alone also decides nothing about the From address a person sees: that is the job of DMARC, which uses the SPF result only when the domain SPF checked matches the domain in From.