SPF checker
Evaluate a domain's SPF record the way a receiving mail server does. Every mechanism, DNS lookup and macro expansion is shown, so you can see not just the verdict but where it came from.
fail
The sending IP is not authorised, and the domain says to reject.
- DNS terms used
- 0 of 10
- Void lookups
- 0 of 2
- DNS queries
- 1
- Elapsed
- 9 ms
How it was evaluated
-
record for spf.protection.outlook.com
v=spf1 ip4:40.92.0.0/15 ip4:40.107.0.0/16 ip4:52.100.0.0/15 ip4:52.102.0.0/16 ip4:52.103.0.0/17 ip4:104.47.0.0/17 ip6:2a01:111:f400::/48 ip6:2a01:111:f403::/49 ip6:2a01:111:f403:8000::/51 ip6:2a01:111:f403:c000::/51 ip6:2a01:111:f403:f000::/52 -all -
ip4:40.92.0.0/15no match -
ip4:40.107.0.0/16no match -
ip4:52.100.0.0/15no match -
ip4:52.102.0.0/16no match -
ip4:52.103.0.0/17no match -
ip4:104.47.0.0/17no match -
ip6:2a01:111:f400::/48no match -
ip6:2a01:111:f403::/49no match -
ip6:2a01:111:f403:8000::/51no match -
ip6:2a01:111:f403:c000::/51no match -
ip6:2a01:111:f403:f000::/52no match -
-allfail
DNS queries
| Name | Type | Result | Source | Time |
|---|---|---|---|---|
spf.protection.outlook.com |
TXT | NOERROR | dns | 8.7 ms |
Answers marked shared cache came from a
recent check by someone else and cost no network round trip;
cache means the same name was needed twice within this one
evaluation. Entries expire after a minute, so if you have just changed a
record, allow that long before the change shows here.