How to use it
- 1
Enter the sender domain.
- 2
Run the SPF TXT check.
- 3
Review SPF count, mechanisms, final all policy, and lookup risk.
What the tool can do
- Finds v=spf1 TXT records.
- Flags duplicate SPF records.
- Checks permissive all policy and estimated DNS-lookup mechanisms.
Common use cases
- Find missing SPF or two SPF records.
- Check whether the domain is open via +all/?all.
- Prepare for DMARC/DKIM hardening.
How it works inside
The tool checks DNS TXT policy and does not promise final email deliverability.
Lookup risk is estimated from visible mechanisms without recursive include-chain expansion.
Questions and answers
Is -all always better than ~all?
-all is stricter, but move to it only after verifying all legitimate senders or outbound mail can break.
Does SPF guarantee deliverability?
No. SPF is only one part of email authentication; DKIM, DMARC, reputation, and sending infrastructure still matter.
