What it checks
The domain's SPF record: whether there is exactly one, whether it parses, whether it ends in a policy that rejects other senders, and whether evaluating it stays within 10 DNS lookups.
A pass means: An SPF record lists the servers allowed to send mail for the domain.
Possible findings
No SPF record
Severity: MediumConfidence: ConfirmedKind: Security issue
What we found
The domain does not publish an SPF record.
Why it matters
Without SPF, receiving mail servers cannot tell which servers may send mail for your domain, making it easier to send convincing phishing as you.
How to fix it
Publish a TXT record starting v=spf1 that lists the services that send your mail and ends in -all or ~all, for example v=spf1 include:_spf.google.com -all.
More than one SPF record
Severity: MediumConfidence: ConfirmedKind: Security issue
What we found
The domain publishes more than one SPF record.
Why it matters
The SPF standard treats multiple records as an error, so receivers ignore SPF for your domain entirely.
How to fix it
Merge the records into a single v=spf1 TXT record.
SPF allows any server to send
Severity: HighConfidence: ConfirmedKind: Security issue
What we found
The SPF record ends in +all or ?all, so it does not reject any sender.
Why it matters
An SPF record that allows everyone gives no protection against spoofing, and +all actively vouches for forged mail.
How to fix it
End the record with -all (or ~all while testing) after listing your real sending services.
SPF needs too many DNS lookups
Severity: MediumConfidence: High confidenceKind: Security issue
What we found
Evaluating the SPF record needs more than the 10 DNS lookups the standard allows.
Why it matters
Receivers stop evaluating after 10 lookups and treat the result as an error, so legitimate mail may fail SPF.
How to fix it
Remove unused includes, replace a/mx/ptr mechanisms with IP ranges where stable, or use your provider's flattened include.
SPF record has errors
Severity: MediumConfidence: High confidenceKind: Security issue
What we found
The SPF record contains syntax that receivers will reject.
Why it matters
Receivers treat a malformed record as an error, which usually means no SPF protection.
How to fix it
Correct the record. Each term must be a valid mechanism (ip4:, ip6:, include:, a, mx, exists:) or modifier (redirect=, exp=).

