CloudSpex

Free email security tool

Free SPF Record Checker

Check whether your domain publishes an SPF record and identify whether the policy is missing, valid or risky.

CloudSpex explains what the detected SPF result means and what should be changed next.

Enter a domain such as example.com. The checker reads the public SPF policy.

What is an SPF record?

SPF is a DNS-based email policy that identifies permitted sending infrastructure for a domain. It is one email authentication signal and should be reviewed alongside DKIM and DMARC.

What does CloudSpex check?

Record presence

Whether a public SPF record is available.

Multiple records

Whether more than one SPF record is published in the same DNS response.

Terminal policy

Whether a terminal +all, ?all, ~all or -all mechanism can be determined.

CloudSpex currently checks whether an SPF record is present, whether multiple SPF records are published, and which terminal all policy is used when it can be determined. It does not currently evaluate recursive includes, redirect chains, macro expansion, void lookups, SPF flattening or the full 10-DNS-lookup graph.

SPF checker vs email security check

SPF Record Checker

Focuses on one SPF record, multiple-record risk and its terminal policy when safely available.

Email Security Check

Reviews SPF, DKIM and DMARC together as a broader email-security summary.

Why restrictive SPF policies matter

A restrictive -all policy is often the intended end state after all legitimate senders are identified. Softfail and neutral policies can be useful transitional states, but +all does not restrict senders.

Frequently asked questions

What is an SPF record?

An SPF record is a public DNS record that identifies which mail servers may send email for a domain. Receiving servers can use it as one signal when evaluating whether a message is authorized.

What does the CloudSpex SPF checker test?

CloudSpex checks whether an SPF record is present, whether multiple SPF records are published, and which terminal all policy is used when it can be determined.

What does +all mean in an SPF record?

+all allows any sender to pass SPF. It is generally a high-risk policy because it does not restrict which mail servers may send for the domain.

What is the difference between ?all, ~all and -all?

?all is neutral, ~all is softfail, and -all is a restrictive fail policy. Review legitimate senders before changing an SPF policy.

Can a domain have more than one SPF record?

No. Publishing more than one SPF record for the same domain makes SPF evaluation invalid. Combine authorized senders into one record instead.

What happens if a domain has no SPF record?

Receiving servers have no SPF policy for the domain to evaluate. Create a single SPF record after identifying every legitimate sender.

Does CloudSpex test the 10-DNS-lookup limit?

No. The current public checker does not resolve the complete include and redirect graph or calculate the full 10-DNS-lookup limit.

Does the checker make changes to DNS?

No. CloudSpex reads public-facing signals only. It does not change DNS records, email configuration or domain settings.

SPF policies can change without warning.

Add your domain to CloudSpex to monitor SPF, DKIM, DMARC and related email-security configuration changes.

Start Monitoring FreeCheck Another Domain