About this tool

SPF is one of the three building blocks of email authentication alongside DKIM and DMARC, and checking it is a common early step when assessing whether a suspicious email's domain has any sender authorization configured at all.

Example inputs: example.comdigitpol.coma-supplier-domain.com

What the result shows

SPF record text
The full v=spf1 string as published in the domain's TXT records.
Mechanisms
Elements such as include, a, mx and ip4/ip6 that list authorized sending sources; this tool displays the raw string rather than expanding includes.
All qualifier
The final directive, such as -all for fail or ~all for softfail, showing how strictly unauthorized senders are treated.
Record presence
Whether any SPF record was found at all, since a missing record is itself informative.

Investigation use cases

  • Checking whether a domain used in a suspicious email publishes an SPF record at all
  • Comparing SPF strictness (-all versus ~all) between a genuine domain and an impersonator
  • Supporting an email security review before enabling a new outbound sending service
  • Documenting a domain's SPF configuration as part of an evidence record

Limitations

This tool shows the published record only, it does not evaluate a specific sending IP against the record, does not expand nested include mechanisms, and does not perform a full SPF policy evaluation as a receiving mail server would.

Frequently asked questions

Does this tell me if a specific email passed SPF?

No, full SPF evaluation against a sending IP is not performed here; this tool only retrieves and displays the published record text.

What does a missing SPF record mean?

It means the domain has not published any sender authorization policy, which does not prove malice but is a relevant gap worth noting in an investigation.

Does SPF alone stop spoofing of the visible From address?

No, SPF checks the envelope sender domain, not necessarily the visible From address; DMARC alignment is what connects the two.

Is the lookup free?

Yes, within daily limits; a sealed report is a paid or account feature.

Need evidence you can keep?

Every lookup produces a full public-source report sealed with a SHA-256 digest. Accounts keep a saved history and can download the DIGITPOL PDF report.