SPF Validator
Check your Sender Policy Framework setup to ensure your Email Health is protected and only safe sources are verified.
Understanding SPF & Email Deliverability
Sender Policy Framework (SPF) is a critical DNS record that protects your domain from spoofing and ensures your cold emails land in the inbox.
What is an SPF Record?
An SPF record is a TXT record in your domain's DNS that explicitly lists the IP addresses and mail servers authorized to send emails on your behalf. When a receiving server (like Gmail or Outlook) gets an email from you, it checks this record to verify the sender's identity. If the sending IP isn't listed, the email is flagged as spam or rejected.
The 10 DNS Lookup Limit
To prevent Denial of Service (DoS) attacks, the SPF protocol strictly caps DNS lookups at 10. Every "include", "a", and "mx" mechanism in your record counts towards this limit. If your tree (including third-party services like Google, SendGrid, or Chargebee) exceeds 10 lookups, your SPF will permanently fail (PermError), destroying your deliverability.
Soft Fail (~all) vs Hard Fail (-all)
The mechanism at the end of your record tells receivers how strictly to enforce the rules. A Soft Fail (~all) means unauthorized emails are suspicious but should still be delivered (usually to the spam folder). A Hard Fail (-all) explicitly instructs receiving mail servers to drop and reject any unauthorized emails entirely, providing maximum protection.
SPF Flattening Explained
If you rely on multiple SaaS platforms, it's easy to breach the 10 lookup limit. SPF Flattening solves this by recursively resolving all your included domains and replacing them with their raw IP addresses (ip4/ip6 blocks). Because IP mechanisms do not require DNS queries, flattening eliminates the lookup limit issue entirely while keeping your authentication intact.