Record presence
Whether a public SPF record is available.
Free email security tool
Check whether your domain publishes an SPF record and identify whether the policy is missing, valid or risky.
CloudSpex explains what the detected SPF result means and what should be changed next.
SPF is a DNS-based email policy that identifies permitted sending infrastructure for a domain. It is one email authentication signal and should be reviewed alongside DKIM and DMARC.
Whether a public SPF record is available.
Whether more than one SPF record is published in the same DNS response.
Whether a terminal +all, ?all, ~all or -all mechanism can be determined.
CloudSpex currently checks whether an SPF record is present, whether multiple SPF records are published, and which terminal all policy is used when it can be determined. It does not currently evaluate recursive includes, redirect chains, macro expansion, void lookups, SPF flattening or the full 10-DNS-lookup graph.
Focuses on one SPF record, multiple-record risk and its terminal policy when safely available.
Reviews SPF, DKIM and DMARC together as a broader email-security summary.
A restrictive -all policy is often the intended end state after all legitimate senders are identified. Softfail and neutral policies can be useful transitional states, but +all does not restrict senders.
An SPF record is a public DNS record that identifies which mail servers may send email for a domain. Receiving servers can use it as one signal when evaluating whether a message is authorized.
CloudSpex checks whether an SPF record is present, whether multiple SPF records are published, and which terminal all policy is used when it can be determined.
+all allows any sender to pass SPF. It is generally a high-risk policy because it does not restrict which mail servers may send for the domain.
?all is neutral, ~all is softfail, and -all is a restrictive fail policy. Review legitimate senders before changing an SPF policy.
No. Publishing more than one SPF record for the same domain makes SPF evaluation invalid. Combine authorized senders into one record instead.
Receiving servers have no SPF policy for the domain to evaluate. Create a single SPF record after identifying every legitimate sender.
No. The current public checker does not resolve the complete include and redirect graph or calculate the full 10-DNS-lookup limit.
No. CloudSpex reads public-facing signals only. It does not change DNS records, email configuration or domain settings.
Add your domain to CloudSpex to monitor SPF, DKIM, DMARC and related email-security configuration changes.
Start Monitoring FreeCheck Another Domain