SPF check

Sender Policy Framework decides which servers are allowed to send mail for your domain. This check grades the verdict for the message you sent, then inspects the record itself.

What this check looks at

SPF (Sender Policy Framework) is a DNS TXT record that lists the servers permitted to send mail for a domain. When your test message arrives, JoltMx records the SPF verdict for the connecting IP, then re-reads the published record to check it for the faults that quietly break SPF:

  • The verdict for the sending IP - pass, fail, softfail, neutral, or an error.
  • Whether the domain publishes exactly one SPF record (more than one is a permanent error).
  • The final all qualifier - -all, ~all, ?all, or the dangerous +all.
  • The DNS lookup count - the record must resolve within the RFC 7208 limit of 10 lookups.

Why it matters

SPF is one of the two pillars (with DKIM) that receivers use to decide whether mail is genuine. Major providers require SPF or DKIM to accept mail at all, and both for bulk senders. A failing or broken SPF record is a fast track to rejection - and a permissive one (+all) actively invites spoofing of your domain.

How the diagnostic grades it

ResultSeverityWhat it means
SPF passedPassThe sending IP is authorised by the domain.
No SPF recordCriticalThe domain publishes none. Publish a record starting v=spf1.
SPF failedCriticalThe sending IP isn't in the record. Add it, or relay through an authorised host.
Record is broken (permerror)CriticalSyntax error - treated like a hard fail by many receivers.
Duplicate recordsCriticalMore than one v=spf1 record. Merge into one.
Allows any sender (+all)CriticalAuthorises the whole internet. Replace with ~all or -all.
Lookup limit exceededCriticalOver 10 DNS lookups - SPF effectively never passes. Flatten includes.
Soft-fail / neutral / no allWarningWeak protection; raises spam scoring. End with ~all or -all.
Lookup budget nearly exhaustedWarning9 of 10 lookups used - one more include is likely to break SPF.
Temporary errorInfoDNS was briefly unavailable during evaluation. Re-test.

How to fix it

A healthy record lists your senders and ends with a strict qualifier:

v=spf1 include:joltmx.io ~all
  • Keep one record only. If you send through several providers, merge their include: terms into the single record.
  • End with ~all (soft fail) or -all (hard fail) - never +all.
  • If you're near the 10-lookup limit, remove unused include: terms or flatten them to IP ranges.
SPF alone doesn't survive forwarding - the forwarder's IP isn't in your record. That's expected, and why DKIM and ARC exist. See message type for how to read SPF on forwarded mail.

Related checks

DKIM · DMARC · From alignment · SPF, DKIM & DMARC explained

Free during beta

Start routing mail in minutes.

Point your MX records at JoltMx. Add a domain. Create your first rule. Done.

No credit card required  ·  Free tier stays free