SPF Record Checker

Validate your SPF record and count the DNS lookups it really uses. Crossing the limit of 10 silently breaks SPF for every message you send.

How it works

SPF lists the servers allowed to send mail for your domain. Receivers evaluate it on every message; a PermError counts as a failure and hurts DMARC alignment.

Each include, a, mx, ptr, exists and redirect costs one DNS lookup, and includes are followed recursively. We walk the whole tree, so the count you see is what receivers see.

Common problems we flag: more than one SPF record, +all (anyone may send as you), ?all (no protection), the deprecated ptr mechanism, and includes pointing at domains with no SPF.

Automate it with the API

Run this check for every address in your product, from any language.

curl -X POST "https://www.mailrambo.com/v1/verify?detail=full" \
  -H "Authorization: Bearer $MAILRAMBO_KEY" \
  -H "Content-Type: application/json" \
  -d '{"email": "jane@acme.com"}'
# -> detail.dns: { spf, dmarc_policy, dkim_selectors, bimi, ptr, mx_hosts }

API reference · Get a free API key

Frequently asked questions

What is the SPF 10 lookup limit?

RFC 7208 caps SPF evaluation at 10 DNS-querying terms. Beyond that, receivers return PermError and treat SPF as failed.

How do I reduce SPF lookups?

Remove providers you no longer use, replace includes with ip4/ip6 ranges where the provider publishes fixed IPs, or move a sending service to a subdomain with its own SPF record.

Should SPF end in ~all or -all?

Both are fine once DMARC is enforced. ~all (soft fail) is the safer default while you are still discovering all your senders.

Can I have two SPF records?

No. Multiple v=spf1 records cause a PermError. Merge them into one.

Run these checks from your code

Verify addresses at signup, clean lists and read SPF/DKIM/DMARC with one API call. 100 free verifications a month, test keys that cost nothing, and the API on every plan.