SPF record checker
Read a domain's SPF record the way a receiving mail server does, and see what would make it fail.
- Every mechanism and include expanded
- DNS lookup count against the limit of 10
- Plain-English findings
Give it something to look up — Glee will do the digging.
How the spf checker works
SPF (Sender Policy Framework) is a DNS record listing the servers allowed to send mail for a domain. Receiving servers check it on every message; if the sending server is not covered, the message can be rejected or sent to spam, and if the record itself is broken, every message is at risk.
This checker fetches the domain's SPF record and evaluates it as a receiver would: it expands each include, counts the DNS lookups the record needs (the standard allows ten; one more and the whole record fails), and reports duplicate records, syntax errors and an overly permissive ending such as +all. Each finding is explained in plain words.
SPF is one of three records that work together. A domain with SPF but no DMARC policy tells receivers who may send but not what to do when someone else does.
What each field means
- Record
- The TXT record beginning v=spf1.
- Lookup count
- DNS lookups needed to evaluate the record; more than 10 is a permanent error.
- Findings
- Each problem, with its severity.
Where this check stops
- A published SPF record alone is not a pass: it is evaluated against the sending server of each message.
- DNS answers can be cached for up to an hour.
The same check, through the API
Same calculation, same answer, with a key. 3 credits per check ($0.30 per 1,000). A free account includes 1,000 credits a month.
GET /v1/email-auth/acme.com Host: gleanzy.com Authorization: Bearer $GLEANZY_KEY
Frequently asked
What does ~all mean?
Soft fail: mail from other servers should be accepted but marked. -all asks receivers to reject it.
Why does the lookup count matter?
Receivers stop after ten DNS lookups and treat the record as broken, so large include chains silently fail.