Enter a domain to look up its SPF record and validate it the way Gmail and Outlook do: one record only, no more than 10 DNS lookups counted through every include, readable IP terms, and an ending that is not +all. Each problem comes with the exact change to make.
Checking DKIM too? It needs a selector, so this page skips it. The free deliverability checker reads SPF, DKIM, DMARC and MX in one go.
SPF (Sender Policy Framework) is one TXT record on your domain that lists the servers allowed to send email as you. A receiving server reads it left to right and stops at the first term that matches the sending IP. Four kinds of term do nearly all the work:
Only one v=spf1 record is allowed. With two, receivers ignore both. Merge every sender into one record.
Beforev=spf1 include:_spf.google.com ~all
v=spf1 include:sendgrid.net ~allAfterv=spf1 include:_spf.google.com include:sendgrid.net ~allMeasured in September 2026, this stack needs 12 lookups once the includes nested inside each vendor's record are counted. Remove tools you no longer send from, or replace an include with the ip4: ranges it resolves to.
Beforev=spf1 include:_spf.google.com include:spf.protection.outlook.com include:mailgun.org include:servers.mcsv.net include:_spf.salesforce.com include:sendgrid.net ~allAfterv=spf1 include:_spf.google.com include:sendgrid.net ip4:198.51.100.20 ~all+all authorizes every server on the internet, so receivers discount the record completely.
Beforev=spf1 include:_spf.google.com +allAfterv=spf1 include:_spf.google.com ~allOne term a receiver cannot parse is a permanent error that voids the whole record.
Beforev=spf1 ip4:2001:db8::25 ~allAfterv=spf1 ip6:2001:db8::25 ~allWithout an all term, each receiver decides for itself what to do with unlisted senders.
Beforev=spf1 include:_spf.google.comAfterv=spf1 include:_spf.google.com ~allRead the record left to right. Every include, a, mx and redirect costs a DNS lookup, and a record that needs more than ten fails outright (permerror). Count before you add another vendor.

SPF lives at your DNS host (Cloudflare, GoDaddy, Namecheap, Route 53), not at your email provider. Open the TXT records for the bare domain, find the one starting with v=spf1, and edit it in place rather than adding a second one. Changes usually show up within minutes and always within the record's TTL, often an hour. Then run this check again.
SPF on its own does not get cold email into the inbox; Gmail and Yahoo also want DKIM and a DMARC record, and they judge alignment between all three. The walkthrough in SPF, DKIM and DMARC for cold email has the exact values for Google Workspace and Microsoft 365, and the DMARC checker reads the policy that ties them together.
Enter your domain above. The checker reads the TXT record that starts with v=spf1, follows every include: to count the DNS lookups it costs, and flags the four mistakes that make receivers ignore it: more than one SPF record, more than 10 lookups, an unreadable ip4: or ip6: term, and an ending of +all. You can also run nslookup -type=txt yourdomain.com, but that shows the record without counting nested lookups.
RFC 7208 caps SPF evaluation at 10 DNS lookups. Every include:, a, mx, ptr, exists and redirect= costs one, and so does every lookup inside the records you include. Past 10, receivers return a permanent error (permerror) and treat the domain as having no SPF at all. A common stack of Google Workspace, Microsoft 365, Mailgun, Mailchimp, Salesforce and SendGrid needed 12 when we counted in September 2026.
Either is fine for deliverability. ~all (soft fail) asks receivers to accept unlisted senders but mark them suspicious; -all (hard fail) says to reject them. Start with ~all while you confirm every tool that sends for you is listed, then move to -all. Never use +all, which authorizes every server on the internet, and avoid ?all, which receivers give almost no weight.
No. A domain may publish exactly one TXT record starting with v=spf1. With two, receivers return a permanent error and ignore SPF entirely, the same as having none. It usually happens when a new email tool is added as a second record instead of as an include: in the existing one. Merge them into one record.
DKIM keys live at a selector you choose (for example google._domainkey.yourdomain.com), and there is no public way to list a domain's selectors. The full deliverability checker tries the selectors the major providers use and also reads DMARC and MX, so run that for the complete picture.
Check any domain's SPF, DKIM, DMARC, and MX records in seconds.
Look up a DMARC policy, reporting address, pct and alignment.
Check a domain or mail server IP against Spamhaus, SURBL, URIBL and more.
Scan a subject line and email body for spam-trigger phrases.
Get a day-by-day sending ramp schedule for a new or existing mailbox.
Check text-to-HTML ratio, images, links, and tracking pixels in an email.
Warmerly re-checks SPF, DKIM, DMARC and blocklists on every sending domain daily and warms your mailboxes while it does. Free plan, no card. Paid plans from $19/month.