SPF.Guru

SPF checker

Evaluate a domain's SPF record the way a receiving mail server does. Every mechanism, DNS lookup and macro expansion is shown, so you can see not just the verdict but where it came from.

A bare domain works too

IPv4 or IPv6

Defaults to the sender domain

Evaluated instead of the published record, so you can test one before publishing it. Includes inside it still resolve live.

fail

The sending IP is not authorised, and the domain says to reject.

DNS terms used
0 of 10
Void lookups
0 of 2
DNS queries
1
Elapsed
9 ms

How it was evaluated

  1. record for spf.protection.outlook.com v=spf1 ip4:40.92.0.0/15 ip4:40.107.0.0/16 ip4:52.100.0.0/15 ip4:52.102.0.0/16 ip4:52.103.0.0/17 ip4:104.47.0.0/17 ip6:2a01:111:f400::/48 ip6:2a01:111:f403::/49 ip6:2a01:111:f403:8000::/51 ip6:2a01:111:f403:c000::/51 ip6:2a01:111:f403:f000::/52 -all
  2. ip4:40.92.0.0/15 no match
  3. ip4:40.107.0.0/16 no match
  4. ip4:52.100.0.0/15 no match
  5. ip4:52.102.0.0/16 no match
  6. ip4:52.103.0.0/17 no match
  7. ip4:104.47.0.0/17 no match
  8. ip6:2a01:111:f400::/48 no match
  9. ip6:2a01:111:f403::/49 no match
  10. ip6:2a01:111:f403:8000::/51 no match
  11. ip6:2a01:111:f403:c000::/51 no match
  12. ip6:2a01:111:f403:f000::/52 no match
  13. -all fail

DNS queries

NameTypeResultSourceTime
spf.protection.outlook.com TXT NOERROR dns 8.7 ms

Answers marked shared cache came from a recent check by someone else and cost no network round trip; cache means the same name was needed twice within this one evaluation. Entries expire after a minute, so if you have just changed a record, allow that long before the change shows here.