Enter a domain — an existing SPF record is loaded into the fields below.

The lookup limit, before it hurts

SPF permits at most ten DNS lookups, counted recursively across every include: chain. Exceed the limit and the record is not "partly valid" — it returns permerror, and many receivers treat that as "no SPF at all". The part that worked before stops working too.

That is exactly what this generator makes visible: every draft is actually resolved — each include: followed, each a and mx really queried — so you see the number before the record goes into DNS. Afterwards it runs through the same RFC 7208 audit as the check page.

Adjusting an existing record

Enter the domain, press "Build record": an existing SPF record is parsed and fills the fields. Mechanisms the form has no dedicated field for — a:host, exists:, macros — are recognised and carried over unchanged instead of quietly disappearing on rebuild.

Mechanism order is not arbitrary

SPF evaluates left to right. ip4: and ip6: cost no DNS lookup at all, while include:, a and mx cost at least one each. The generator therefore puts the IP literals first: a large share of queries is answered before the lookup budget is touched.

Which all qualifier

  • -all (hardfail) — anything not in the record is not authorised. The goal. Set it once you are confident every sending system is covered.
  • ~all (softfail) — not authorised, but please only mark it. The right intermediate step while you are still collecting. Too weak as a permanent state.
  • ?all (neutral) — the domain makes no statement. Offers practically no protection.
  • +all — anyone may send in your name. In practice always a misconfiguration.

When the budget runs out

  • Remove includes you no longer use. The most common find: the newsletter tool from three years ago is still in there.
  • Replace mx. It costs one lookup and additionally resolves every MX host. If you only send through one provider, you do not need it.
  • IP literals instead of includes wherever the provider names fixed addresses — those cost zero lookups.
  • Separate subdomains for bulk sending: news.yourdomain gets its own SPF record with its own budget.

Publishing

The record goes in as a TXT entry on the domain itself, not on a sub-name. A domain may have exactly one SPF record — two produce permerror. You can verify the result afterwards with the SPF check.

The full analysis

Send any email to hello@analyzemy.email and within seconds you get back a report with over 20 checks — for the actual sending IP, including DKIM, DMARC evaluation, the TLS path, blacklists and header analysis.

Analyze your email now

Last updated: · All checks at a glance