SPF Record Badge
Email senders and IT teams can show that a domain publishes a Sender Policy Framework record - and whether it stays inside the 10-lookup limit that makes SPF fail silently when exceeded - with a badge that reads DNS live.
Live preview
Checked live by A2ZShowing the badge for a2z.tools. Enter your domain to see yours.
Embed code
The badge is re-checked automatically (every few hours; every 5 minutes for website status) and cached, so it adds almost nothing to your page load. The link carries rel="nofollow".
Works with
How it works
A2Z reads the domain's TXT records, finds the one that begins v=spf1 and evaluates it with the same parser as the A2Z SPF checker. The parser follows include and redirect mechanisms to count how many DNS lookups a receiving server would need, and notes how the record ends: -all (reject senders not listed), ~all (soft-fail them), ?all (neutral) or +all (allow everyone). No email is sent and nothing is written to DNS.
What is checked
- Found: a TXT record at the domain beginning v=spf1 (RFC 7208 section 4.5)
- Lookup count: include, a, mx, ptr, exists and redirect each cost one lookup; the limit is 10 (RFC 7208 section 4.6.4)
- Green for -all or ~all within the limit; red for +all or more than 10 lookups; amber for ?all or no all mechanism
Limitations
- Does not send or receive test email, so it cannot confirm your mail servers are the ones listed.
- SPF alone does not stop spoofing of the visible From address - DMARC is needed for that.
- A domain that sends no email should publish "v=spf1 -all"; the badge cannot know whether you send email.
Where publishers use it
- IT administrators documenting email authentication
- Email marketing agencies onboarding clients
- Newsletter publishers showing domain hygiene
Questions
Is -all better than ~all?
-all asks receivers to reject unlisted senders; ~all asks them to accept but mark. Both are valid. Many domains start with ~all and move to -all once DMARC reports show no legitimate sender is missing.
Why does the lookup limit matter?
RFC 7208 caps SPF evaluation at 10 DNS lookups. Beyond that, receivers return a permanent error and SPF fails for every message, including genuine ones.
Does SPF stop spoofing on its own?
No. SPF checks the envelope sender, not the From address people see. DKIM and DMARC complete the picture.
Sources
- RFC 7208 - Sender Policy Framework (SPF) - IETF . Section 4.6.4: the 10 DNS-lookup limit.
Cite or recommend this tool
If you reference this tool in an article, course or documentation, these formats are ready to copy. They are optional - nothing is added to your site unless you paste it.
A2Z Tools SPF Record Badge https://a2z.tools/spf-checker
<a href="https://a2z.tools/spf-checker">A2Z Tools SPF Record Badge</a>
[A2Z Tools SPF Record Badge](https://a2z.tools/spf-checker)
SPF Record Badge by A2Z Tools - https://a2z.tools/spf-checker
Related widgets
-
Shows your domain's DMARC policy - p=reject, p=quarantine or p=none.
-
Checks a domain's SPF and DMARC records and DNSSEC status in one go.
-
Shows whether your domain is DNSSEC-signed and validates.
-
A live badge showing that your SSL certificate is valid, trusted and how many days it has left.
-
A badge counting down the days until your SSL certificate expires.
-
Shows whether your site serves HTTPS and redirects plain-HTTP visitors to it.