Email Security
SPF Record Checker & Syntax Validator
Validate Sender Policy Framework (SPF) records according to RFC 7208 standards. SPF is a DNS-based email authentication method that specifies which mail servers are authorized to send email on behalf of your domain. Incorrectly configured SPF records are one of the leading causes of legitimate emails being marked as spam or rejected. Count DNS lookups to avoid exceeding the strict 10-lookup limit, test sending IPs in real-time, and generate optimized, flattened SPF records for maximum deliverability.
Key Capabilities & Features
dnsfyi combines high-speed global Anycast DNS queries with comprehensive security auditing into a unified diagnostic suite.
- • RFC 7208 10-DNS-lookup limit counter with recursive include traversal
- • Real-time IP authorization simulator for sending mail servers
- • Syntax validation for all qualifiers (+, -, ~, ?) and mechanisms (ip4, ip6, a, mx, include, exists)
- • Automated SPF flattening suggestions to eliminate PermError issues
- • Support for redirect= and exp= modifiers
- • BIND zone file and DNS provider-specific format export
How to Use This Tool
To audit any domain or IP address, enter the hostname into the search box to run an instant parallel multi-resolver inspection.
- Enter your domain name in the search field (e.g., yourdomain.com).
- dnsfyi fetches your TXT records and automatically identifies the SPF record (starts with v=spf1).
- Review the DNS lookup counter — if it shows more than 10, your SPF will cause a PermError.
- Use the IP Simulator to test if a specific sending IP (e.g., your mail server) passes SPF.
- If the lookup count exceeds 10, use the SPF Flattening suggestion to inline all includes as static ip4: ranges.
Common Use Cases
dnsfyi is primarily used to troubleshoot email deliverability failures, verify global DNS propagation, and audit SSL certificate health.
- → Diagnosing why legitimate emails are failing SPF checks and landing in spam.
- → Verifying that a newly added email service provider (ESP) is included in your SPF record.
- → Checking if SPF is correctly configured after migrating to Google Workspace or Microsoft 365.
- → Auditing SPF lookup depth to ensure compliance before switching to p=reject DMARC policy.
- → Generating a flattened SPF record to fix PermError caused by too many DNS lookups.
Frequently Asked Questions
Find direct answers about dnsfyi's multi-resolver query engine, privacy policy, domain security checks, and free REST API.
- What is the SPF 10-lookup limit?
- RFC 7208 specifies that an SPF evaluation must not perform more than 10 DNS lookups across all includes, redirects, a, mx, exists, and ptr mechanisms. Exceeding this causes a PermError, which means SPF evaluation fails and legitimate emails can be rejected or spam-flagged.
- What does SPF PermError mean?
- PermError means the SPF record is syntactically invalid or exceeds the 10-DNS-lookup limit. It is a permanent error — receiving mail servers treat it as a policy failure. Fix it by reducing include: chains, flattening SPF into ip4: ranges, or using SPF macros.
- What does SPF SoftFail (~all) vs HardFail (-all) mean?
- ~all (SoftFail) means emails from unauthorized servers are accepted but marked as suspicious. -all (HardFail) means emails from unauthorized servers should be rejected outright. Start with ~all while configuring your policy, then move to -all once all sending sources are confirmed.
- I have multiple SPF records — is that a problem?
- Yes. RFC 7208 mandates that a domain must have exactly one SPF TXT record. Multiple SPF records cause a PermError. Merge all your SPF mechanisms into a single record.
- How do I add Google Workspace to my SPF record?
- Add include:_spf.google.com to your SPF TXT record: v=spf1 include:_spf.google.com ~all. For Microsoft 365: v=spf1 include:spf.protection.outlook.com ~all.
- Does SPF alone protect against email spoofing?
- SPF alone is insufficient. SPF only validates the envelope sender (MAIL FROM), not the visible From: header. You need DMARC to enforce alignment between SPF/DKIM and the From: header, and DKIM to sign message content cryptographically.