SPF Record Validator (RFC 7208)
Is an IP or CIDR range authorized by a domain's SPF?
About the SPF Validation tool
This validator runs the RFC 7208 check_host() algorithm against the domain's SPF record. It follows include and redirect, resolves a and mx mechanisms, expands macros and enforces the 10-lookup and 2-void-lookup limits.
Enter a CIDR range to test a whole block at once. A range passes only if every address in it is authorized. Otherwise the results break the range into sub-ranges and show the result for each one, with the mechanism that decided it.
Terms whose outcome depends on each individual address (ptr, or macros such as %{i}) are evaluated address by address for ranges of up to 256 addresses.
Frequently asked questions
What is the difference between fail and softfail?
-all (fail) asks receivers to reject unauthorized mail. ~all (softfail) asks them to accept it but treat it as suspicious. DMARC typically treats both as SPF failure.
Which sender address is assumed?
Evaluation uses postmaster@ the domain you enter as the envelope sender, which matters only for records that use sender macros.