SPF Validator API

GET

Catch broken SPF records and verify authorized sending IPs.

SPF Validator checks the Sender Policy Framework (SPF) DNS record for a domain to verify if it’s valid and optionally whether a given IP address is authorized to send emails for that domain.

Try it — live request, no key required

Request
GETapi.apiverve.com/v1/spfvalidator?domain=myspace.com
Query parameters
Verification
Format

No key required to try it. Get a key to use it in your app.

Example
{
  "status": "ok",
  "error": null,
  "data": {
    "host": "myspace.com",
    "has_spf_record": true,
    "dns_lookups_num": 9,
    "spf_record": "v=spf1 mx ip4:63.208.226.34 ip4:204.16.32.0/22 ip4:67.134.143.0/24 ip4:216.205.243.0/24 ip4:34.85.156.5/32 ip4:35.245.108.108/32 ip4:34.86.129.193/32 ip4:34.86.134.94/32 ip4:34.85.222.234/32 ip4:34.86.176.234/32 ip4:34.86.125.212/32 ip4:34.85.224.60/32 ip4:34.86.160.49/32 ip4:35.245.64.166/32 ip4:35.188.226.11/32 ip4:34.86.208.228/32 ip4:34.85.216.144/32 ip4:35.221.22.153/32 ip4:34.86.137.108/32 ip4:34.86.51.35/32 ip4:34.150.221.40/32 ip4:34.85.216.70/32 ip4:34.86.37.191/32 ip4:34.85.214.215/32 ip4:35.236.234.82/32 ip4:34.86.161.241/32 ip4:216.32.181.16 ip4:216.178.32.0/20 ip4:168.235.224.0/24 include:_netblocks.mimecast.com -all",
    "spf_records_list": [
      {
        "origin": "myspace.com",
        "record": "v=spf1 mx ip4:63.208.226.34 ip4:204.16.32.0/22 ip4:67.134.143.0/24 ip4:216.205.243.0/24 ip4:34.85.156.5/32 ip4:35.245.108.108/32 ip4:34.86.129.193/32 ip4:34.86.134.94/32 ip4:34.85.222.234/32 ip4:34.86.176.234/32 ip4:34.86.125.212/32 ip4:34.85.224.60/32 ip4:34.86.160.49/32 ip4:35.245.64.166/32 ip4:35.188.226.11/32 ip4:34.86.208.228/32 ip4:34.85.216.144/32 ip4:35.221.22.153/32 ip4:34.86.137.108/32 ip4:34.86.51.35/32 ip4:34.150.221.40/32 ip4:34.85.216.70/32 ip4:34.86.37.191/32 ip4:34.85.214.215/32 ip4:35.236.234.82/32 ip4:34.86.161.241/32 ip4:216.32.181.16 ip4:216.178.32.0/20 ip4:168.235.224.0/24 include:_netblocks.mimecast.com -all",
        "chars_num": 637,
        "use_macro": false,
        "domains": [
          "_netblocks.mimecast.com"
        ],
        "authorized_ips": {
          "ipv4": [
            "63.208.226.34",
            "204.16.32.0/22",
            "67.134.143.0/24",
            "216.205.243.0/24",
            "34.85.156.5/32",
            "35.245.108.108/32",
            "34.86.129.193/32",
            "34.86.134.94/32",
            "34.85.222.234/32",
            "34.86.176.234/32",
            "34.86.125.212/32",
            "34.85.224.60/32",
            "34.86.160.49/32",
            "35.245.64.166/32",
            "35.188.226.11/32",
            "34.86.208.228/32",
            "34.85.216.144/32",
            "35.221.22.153/32",
            "34.86.137.108/32",
            "34.86.51.35/32",
            "34.150.221.40/32",
            "34.85.216.70/32",
            "34.86.37.191/32",
            "34.85.214.215/32",
            "35.236.234.82/32",
            "34.86.161.241/32",
            "216.32.181.16",
            "216.178.32.0/20",
            "168.235.224.0/24"
          ]
        }
      },
      {
        "origin": "_netblocks.mimecast.com",
        "record": "v=spf1 include:eu._netblocks.mimecast.com include:us._netblocks.mimecast.com include:za._netblocks.mimecast.com include:de._netblocks.mimecast.com include:au._netblocks.mimecast.com include:ca._netblocks.mimecast.com include:usb._netblocks.mimecast.com ~all",
        "chars_num": 257,
        "use_macro": false,
        "domains": [
          "eu._netblocks.mimecast.com",
          "us._netblocks.mimecast.com",
          "za._netblocks.mimecast.com",
          "de._netblocks.mimecast.com",
          "au._netblocks.mimecast.com",
          "ca._netblocks.mimecast.com",
          "usb._netblocks.mimecast.com"
        ]
      },
      {
        "origin": "eu._netblocks.mimecast.com",
        "record": "v=spf1 ip4:195.130.217.0/24 ip4:91.220.42.0/24 ip4:146.101.78.0/24 ip4:207.82.80.0/24 ip4:213.167.81.0/25 ip4:193.7.207.0/25 ip4:213.167.75.0/25 ip4:185.58.85.0/24 ip4:185.58.86.0/24 ip4:193.7.206.0/25 ip4:147.28.36.0/24 ~all",
        "chars_num": 225,
        "use_macro": false,
        "authorized_ips": {
          "ipv4": [
            "195.130.217.0/24",
            "91.220.42.0/24",
            "146.101.78.0/24",
            "207.82.80.0/24",
            "213.167.81.0/25",
            "193.7.207.0/25",
            "213.167.75.0/25",
            "185.58.85.0/24",
            "185.58.86.0/24",
            "193.7.206.0/25",
            "147.28.36.0/24"
          ]
        }
      },
      {
        "origin": "us._netblocks.mimecast.com",
        "record": "v=spf1 ip4:207.211.31.0/25 ip4:205.139.110.0/24 ip4:216.205.24.0/24 ip4:170.10.129.0/24 ip4:63.128.21.0/24 ip4:170.10.133.0/24 ip4:185.58.84.93/32 ip4:207.211.41.113/32 ip4:207.211.30.64/26 ip4:207.211.30.128/25 ip4:216.145.221.0/24 ip4:170.10.128.0/24 ip4:170.10.132.56/29 ip4:170.10.132.64/29 ~all",
        "chars_num": 299,
        "use_macro": false,
        "authorized_ips": {
          "ipv4": [
            "207.211.31.0/25",
            "205.139.110.0/24",
            "216.205.24.0/24",
            "170.10.129.0/24",
            "63.128.21.0/24",
            "170.10.133.0/24",
            "185.58.84.93/32",
            "207.211.41.113/32",
            "207.211.30.64/26",
            "207.211.30.128/25",
            "216.145.221.0/24",
            "170.10.128.0/24",
            "170.10.132.56/29",
            "170.10.132.64/29"
          ]
        }
      },
      {
        "origin": "za._netblocks.mimecast.com",
        "record": "v=spf1 ip4:41.74.192.0/22 ip4:41.74.200.0/23 ip4:41.74.196.0/22 ip4:41.74.204.0/23 ip4:41.74.206.0/24 ~all",
        "chars_num": 106,
        "use_macro": false,
        "authorized_ips": {
          "ipv4": [
            "41.74.192.0/22",
            "41.74.200.0/23",
            "41.74.196.0/22",
            "41.74.204.0/23",
            "41.74.206.0/24"
          ]
        }
      },
      {
        "origin": "de._netblocks.mimecast.com",
        "record": "v=spf1 ip4:51.163.158.0/24 ip4:194.104.109.0/24 ip4:194.104.111.0/24 ip4:194.104.110.21/32 ip4:194.104.110.240/28 ip4:62.140.10.21/32 ip4:62.140.7.0/24 ip4:194.104.108.240/29 ip4:194.104.108.21/32 ip4:51.163.159.0/24 ~all",
        "chars_num": 221,
        "use_macro": false,
        "authorized_ips": {
          "ipv4": [
            "51.163.158.0/24",
            "194.104.109.0/24",
            "194.104.111.0/24",
            "194.104.110.21/32",
            "194.104.110.240/28",
            "62.140.10.21/32",
            "62.140.7.0/24",
            "194.104.108.240/29",
            "194.104.108.21/32",
            "51.163.159.0/24"
          ]
        }
      },
      {
        "origin": "au._netblocks.mimecast.com",
        "record": "v=spf1 ip4:103.13.69.0/24 ip4:124.47.150.0/24 ip4:124.47.189.0/24 ip4:103.96.23.0/24 ip4:103.96.21.0/24 ip4:180.189.28.0/24 ip4:216.145.217.0/24 ip4:103.96.22.96/28 ip4:103.96.22.22/32 ip4:103.96.20.22/32 ip4:103.96.20.96/28 ~all",
        "chars_num": 229,
        "use_macro": false,
        "authorized_ips": {
          "ipv4": [
            "103.13.69.0/24",
            "124.47.150.0/24",
            "124.47.189.0/24",
            "103.96.23.0/24",
            "103.96.21.0/24",
            "180.189.28.0/24",
            "216.145.217.0/24",
            "103.96.22.96/28",
            "103.96.22.22/32",
            "103.96.20.22/32",
            "103.96.20.96/28"
          ]
        }
      },
      {
        "origin": "ca._netblocks.mimecast.com",
        "record": "v=spf1 ip4:170.10.145.0/24 ip4:170.10.147.0/24 ip4:170.10.144.126/32 ip4:170.10.146.126/32 ip4:170.10.144.240/29 ip4:170.10.146.240/29 ip4:216.145.216.0/24 ~all",
        "chars_num": 160,
        "use_macro": false,
        "authorized_ips": {
          "ipv4": [
            "170.10.145.0/24",
            "170.10.147.0/24",
            "170.10.144.126/32",
            "170.10.146.126/32",
            "170.10.144.240/29",
            "170.10.146.240/29",
            "216.145.216.0/24"
          ]
        }
      },
      {
        "origin": "usb._netblocks.mimecast.com",
        "record": "v=spf1 ip4:170.10.151.0/24 ip4:170.10.153.0/24 ip4:170.10.150.240/29 ip4:170.10.152.240/29 ip4:170.10.156.0/24 ip4:170.10.157.0/24 ~all",
        "chars_num": 135,
        "use_macro": false,
        "authorized_ips": {
          "ipv4": [
            "170.10.151.0/24",
            "170.10.153.0/24",
            "170.10.150.240/29",
            "170.10.152.240/29",
            "170.10.156.0/24",
            "170.10.157.0/24"
          ]
        }
      }
    ],
    "domains_extracted": [
      "myspace.com",
      "_netblocks.mimecast.com",
      "eu._netblocks.mimecast.com",
      "us._netblocks.mimecast.com",
      "za._netblocks.mimecast.com",
      "de._netblocks.mimecast.com",
      "au._netblocks.mimecast.com",
      "ca._netblocks.mimecast.com",
      "usb._netblocks.mimecast.com"
    ],
    "authorized_ips": {
      "ipv4": [
        "63.208.226.34",
        "204.16.32.0/22",
        "67.134.143.0/24",
        "216.205.243.0/24",
        "34.85.156.5/32",
        "35.245.108.108/32",
        "34.86.129.193/32",
        "34.86.134.94/32",
        "34.85.222.234/32",
        "34.86.176.234/32",
        "34.86.125.212/32",
        "34.85.224.60/32",
        "34.86.160.49/32",
        "35.245.64.166/32",
        "35.188.226.11/32",
        "34.86.208.228/32",
        "34.85.216.144/32",
        "35.221.22.153/32",
        "34.86.137.108/32",
        "34.86.51.35/32",
        "34.150.221.40/32",
        "34.85.216.70/32",
        "34.86.37.191/32",
        "34.85.214.215/32",
        "35.236.234.82/32",
        "34.86.161.241/32",
        "216.32.181.16",
        "216.178.32.0/20",
        "168.235.224.0/24",
        "195.130.217.0/24",
        "91.220.42.0/24",
        "146.101.78.0/24",
        "207.82.80.0/24",
        "213.167.81.0/25",
        "193.7.207.0/25",
        "213.167.75.0/25",
        "185.58.85.0/24",
        "185.58.86.0/24",
        "193.7.206.0/25",
        "147.28.36.0/24",
        "207.211.31.0/25",
        "205.139.110.0/24",
        "216.205.24.0/24",
        "170.10.129.0/24",
        "63.128.21.0/24",
        "170.10.133.0/24",
        "185.58.84.93/32",
        "207.211.41.113/32",
        "207.211.30.64/26",
        "207.211.30.128/25",
        "216.145.221.0/24",
        "170.10.128.0/24",
        "170.10.132.56/29",
        "170.10.132.64/29",
        "41.74.192.0/22",
        "41.74.200.0/23",
        "41.74.196.0/22",
        "41.74.204.0/23",
        "41.74.206.0/24",
        "51.163.158.0/24",
        "194.104.109.0/24",
        "194.104.111.0/24",
        "194.104.110.21/32",
        "194.104.110.240/28",
        "62.140.10.21/32",
        "62.140.7.0/24",
        "194.104.108.240/29",
        "194.104.108.21/32",
        "51.163.159.0/24",
        "103.13.69.0/24",
        "124.47.150.0/24",
        "124.47.189.0/24",
        "103.96.23.0/24",
        "103.96.21.0/24",
        "180.189.28.0/24",
        "216.145.217.0/24",
        "103.96.22.96/28",
        "103.96.22.22/32",
        "103.96.20.22/32",
        "103.96.20.96/28",
        "170.10.145.0/24",
        "170.10.147.0/24",
        "170.10.144.126/32",
        "170.10.146.126/32",
        "170.10.144.240/29",
        "170.10.146.240/29",
        "216.145.216.0/24",
        "170.10.151.0/24",
        "170.10.153.0/24",
        "170.10.150.240/29",
        "170.10.152.240/29",
        "170.10.156.0/24",
        "170.10.157.0/24"
      ],
      "ipv6": []
    },
    "issues_found": [],
    "spf_valid": true,
    "has_issues": false,
    "macros_found": false,
    "ip_pass": false,
    "elapsed_ms": 431,
    "all_qualifier": "fail",
    "risk_score": 5,
    "risk_level": "low"
  }
}

About the SPF Validator API

This tool performs a DNS lookup to retrieve the SPF record for the domain and validates its syntax, structure, and IP ranges. When an IP address is provided, the API tests whether it is permitted under the domain’s SPF rules for sending mail.

What people use it for

Outbound Mail Onboarding
Before sending campaign blasts, marketing platforms check customer sender domains to confirm a valid SPF record exists and inspect the all-mechanism qualifier.
Mail Gateway Threat Screening
When incoming messages arrive, mail security gateways test the relay IP against the sender domain's SPF record to flag unauthorized server relays.
DNS Configuration Auditing
Flag syntax errors and missing SPF records across managed domains so IT administrators fix broken mail authentication settings before delivery rates drop.
Sales Outreach Health Checks
Sales engagement tools query sending IP authorization across connected mailboxes to prevent cold outreach from landing in recipient spam folders.

Ways to call it

One endpoint, many ways in — REST with JSON, XML, YAML and CSV, plus GraphQL and an MCP interface for AI agents.

JSON
Default REST response
XML
Markup format
YAML
Human-readable
CSV
Tabular export
Beta
GraphQL
Query language
New
MCP
For AI agents

How it compares

Side by side with the tools people weigh SPF Validator against — what each one is better at, in plain terms.

Other ways to use SPF Validator

Same data, same APIVerve account, same credit balance — one key works on all of them.

Questions.

Common questions about the SPF Validator API.

Read the docs →
Does it test IPv6 addresses as well as IPv4?
Yes. SPF Validator extracts and evaluates both IPv4 and IPv6 addresses and ranges authorized by the domain's SPF record.
How many domain validations does the Free plan cover?
The Free plan includes 20 domain validations each month at 10 credits per call. If you need more volume, the Starter plan covers 20,000 checks per month, which works out to $1.50 per 1,000 checks.
Do I get the spoofing risk score and issue details on the Free plan?
No. The spoofing risk score and risk level require a paid plan. Subscribing to Starter or higher also unlocks the detailed issues list, DNS lookup count, extracted SPF domains, authorized IP lists, macro detection, and processing elapsed time.
Are the SPF records checked in real time?
Yes. SPF Validator performs a real-time DNS lookup on each request to inspect the live SPF record, evaluate its mechanisms, and trace included domains on the fly.
Can I validate a domain's record without testing a specific IP address?
Yes. Passing an IP address is optional. If you only provide a domain name, the check evaluates syntax, qualifiers, and record validity without running an IP pass or fail test.
Can I use the SPF validation results in a commercial product?
Yes, provided you are on a paid plan. You can integrate validation results into your customer-facing onboarding or security dashboards, but you may not resell or redistribute the raw data as a standalone service.

Ready to build with SPF Validator? Start with 200 free credits — one key unlocks all 300+ APIs.

Explore the catalog

300+ APIs on the same key and the same response shape.

Browse all APIs