Check a domain's email authentication
SPF, DKIM, DMARC, MX and BIMI in one request. Including the ten-lookup limit that silently breaks SPF and that most free checkers do not count.
Why the lookup count matters
RFC 7208 caps SPF evaluation at ten DNS lookups. The cap is recursive — every
include: costs one lookup plus everything its own record chains to. Go over
and receivers return permerror, which means SPF stops
authenticating your mail completely.
Nothing in your DNS looks wrong when this happens. The record is still there, still valid to read, still returned by every "is my SPF record OK" tool that only checks syntax. This checker resolves the entire include chain and counts it properly.
Tools
Common failures
Set up a specific provider
Verified SPF include values and live lookup costs for 69 sending platforms.
Worked examples
What 293 well-known domains actually publish — useful for seeing what a real record looks like, and what normal is. Public DNS, resolved 2026-08-04.