SPF record of outlook.com.
Reads a domain's SPF record the way a receiving mail server does: every include, every DNS lookup counted, every mistake named.
Looking up…
How SPF works.
An SPF record is one TXT record on the domain, starting with v=spf1, that lists the servers allowed to send its mail. Receivers read the terms from left to right and stop at the first that matches the sending server: an IP range, the servers of another domain through include:, or all at the end for everything else.
The 10-lookup limit.
Terms that need another DNS lookup (include, a, mx, ptr, exists and redirect) may add up to 10 in total, counting everything the includes pull in. One more, and SPF fails for every message, however correct the rest is. Two lookups that find nothing are also the limit.
Too many lookups? Remove services that no longer send for you, or move a service to a subdomain of its own.
The ending: -all or ~all.
-all(fail): reject mail from anyone not listed.~all(softfail): accept it, but treat it as suspect. The common choice while DMARC does the deciding.?all(neutral) says nothing, and+alllets every server on the internet send as you: never use it.
Common mistakes.
- Two SPF records on one domain. That is a permanent error: merge them into one.
- An
include:of a name with no SPF record, often a typo. That is also a permanent error. ptr: the standard says not to use it.
Questions people ask.
What is an SPF record?
A TXT record starting with v=spf1 that lists the servers allowed to send email for a domain.
What is the SPF 10-lookup limit?
SPF allows at most 10 DNS lookups in total, counting the includes inside includes. Beyond that, SPF fails for every message.
Can a domain have two SPF records?
No. Two records starting with v=spf1 are a permanent error. Merge them into one.
Should my SPF record end in -all or ~all?
~all (softfail) is the common choice while DMARC makes the decision; -all (fail) asks receivers to reject unlisted senders. Never use +all, which lets anyone send as you.
Hivex index
Short names, still free to register.
Starting something new? Hivex keeps a live index of short, brandable .si names nobody has claimed yet, each checked with the registry.
From code, or an AI assistant.
Hivex's free JSON API and MCP server check domains, DNS and registration records from your own code or from AI assistants that speak MCP. No key needed.
More Email tools
- Email deliverability checkerMX, SPF, DKIM, DMARC, MTA-STS, TLS reporting and BIMI in one report.
- DKIM checkerFinds keys at common selectors and checks their type and size.
- DMARC checkerPolicy, alignment and report addresses, checked and explained.
- SPF generatorPick your mail services, get one record that stays under 10 lookups.
- DMARC generatorPolicy, reports and alignment, with a safe rollout path.
- MTA-STS checkerPolicy record, policy file, MX match and TLS reports.
- BIMI checkerRecord, DMARC, SVG logo and VMC or CMC, with a preview.
- Email blacklist checkerAn IP or a domain against live email blocklists.
- Email header analyzerWho sent it, SPF, DKIM, DMARC and every hop, in your browser.
- SMTP testGreeting, STARTTLS and sign-in methods on 587 and 465.
- Domain checkerIs a name free to register? Checked live on any extension.
Sources
- RFC 7208: Sender Policy Framework (SPF), sections 4.6.4, 4.5 and 5.5
- Google: Email sender guidelines (since 1 February 2024)
By Hivex. Updated 10 October 2026. Lookups run live through Cloudflare's public resolver and are kept for at most five minutes.