Tool guide limitationsGuides explain the intended workflow but cannot cover every device, provider or operating condition.
Interfaces and external services can change. Follow the current on-screen controls, check dates and vendor documentation, and verify important results independently before acting on them.
Important: Do not rely on this result alone for purchasing, configuration, security, safety, compliance, contractual or fault-diagnosis decisions. Results can be incomplete, delayed, misleading or wrong. Verify important findings with the relevant provider, manufacturer documentation and an appropriate independent test or qualified professional.
DNS and email
SPF Evaluator guide
Validate an SPF policy and recursively inspect include and redirect branches.
Open SPF EvaluatorWhat you need
- Policy domain
- Optional sender IP, MAIL FROM and HELO/EHLO
How to use it
- 1Enter the policy domain.
- 2Add the real sender details when testing authorisation.
- 3Select Validate SPF.
- 4Review the result, lookup count, warnings and trace.
Understanding the results
- Valid structure does not confirm that every legitimate sender is included.
- More than ten DNS-causing lookups produces an SPF permanent error.
Recommended next actions
- Inventory authorised senders and verify a real message's Authentication-Results.
Common problems
- Duplicate SPF records, recursive includes and incorrect sender scope cause failures.
Privacy and security
- Only public lookup data is requested. Avoid entering internal names, credentials or confidential notes.
Worked example
- Scenario
- Checking a provider include
- Example input
- example.com with sender 203.0.113.10
- How to read it
- The trace shows whether the provider include authorises that address and whether lookup limits are respected.
Limitations
- Receiver-specific PTR and macro state cannot be reproduced completely.
Do not rely on one result for a production, security, safety, purchasing or contractual decision. Verify important findings independently.