Enter your domain and abr.cloud reads its live SPF record — the list of servers allowed to send email as you — tells you whether it's set up safely, and shows the exact fix. Passive and harmless: we only read public DNS.
One quick verification, no account. We store nothing unless you start monitoring.
SPF (Sender Policy Framework) is a DNS record that lists which mail servers may send email for your domain. Receiving servers check it to help decide whether a message claiming to be from you is genuine — so a correct SPF record is your first line of defence against spoofing and a big factor in whether your mail lands in the inbox.
-all (hard fail) or ~all (soft fail) — never +all, which authorises the whole internet.include:s cause a permerror.v=spf1 at your domain root.include: (e.g. include:_spf.google.com), then close with -all.Yes — it runs free with a quick CAPTCHA, no account needed. It reads only your public DNS records.
-all tells receivers to reject mail from servers not in your SPF record (strict); ~all tells them to accept but mark it (soft). -all is stronger once you're sure every legitimate sender is listed.
SPF alone doesn't stop display-name spoofing or protect the visible From address — you need DMARC on top. Run the DMARC test next.
abr.cloud puts 80+ network & security tools behind one fast interface — with AI analysis and always-on monitoring.
open abr.cloud →