Docs/APIs/SPF Validator

SPF Validator

Validate SPF records and test IP authorization

OperationalCredits 5 per callp50 359msDomain DataStar

Overview

This tool performs a DNS lookup to retrieve the SPF record for the domain and validates its syntax, structure, and IP ranges. When an IP address is provided, the API tests whether it is permitted under the domain’s SPF rules for sending mail.

Endpoint

One host, one path per API. The block below shows this call in four languages; every one of them is the same HTTP request. Making requests covers the timeouts, retries and parameter rules that apply to all of them. The SDKs wrap the same call in a typed client.

GEThttps://api.apiverve.com/v1/spfvalidator
curl "https://api.apiverve.com/v1/spfvalidator?domain=myspace.com" \
  -H "x-api-key: your_api_key_here"
const res = await fetch('https://api.apiverve.com/v1/spfvalidator?domain=myspace.com', {
  headers: { 'x-api-key': 'your_api_key_here' },
});

if (!res.ok) throw new Error(`${res.status} ${await res.text()}`);

const { data } = await res.json();
console.log(data);
import requests

res = requests.get(
    "https://api.apiverve.com/v1/spfvalidator?domain=myspace.com",
    headers={"x-api-key": "your_api_key_here"},
    timeout=15,
)
res.raise_for_status()

print(res.json()["data"])
package main

import (
	"fmt"
	"io"
	"net/http"
)

func main() {
	req, _ := http.NewRequest("GET", "https://api.apiverve.com/v1/spfvalidator?domain=myspace.com", nil)
	req.Header.Set("x-api-key", "your_api_key_here")

	res, err := http.DefaultClient.Do(req)
	if err != nil {
		panic(err)
	}
	defer res.Body.Close()

	out, _ := io.ReadAll(res.Body)
	fmt.Println(string(out))
}

Replace your_api_key_here with the key from your dashboard. When the inputs arrive as a list rather than one at a time, batch requests run up to 200 of them through this same API in a single call.

Authentication

Send your key in the x-api-key header. That is the only auth step — there is no token exchange and no per-endpoint scope to configure. Authentication covers creating, rotating and revoking keys.

401 is the only auth verdict

A 401 means the key is missing, invalid or expired. A 403 means the key is valid but not permitted here — blocked by a key restriction or an IP allow-list. Running out of credits is a 429.

Parameters

Sent in the query string. Premium parameters are accepted on every plan but only take effect on plans that include them.

ParameterTypeDescription
domainRequiredstringThe domain to validate the SPF record for
domain

Response

Every API returns the same three top-level keys, so one response handler covers your whole integration: status, error and data. Only data changes shape. Response format covers the envelope, the other output formats and how premium fields are withheld.

Sample response
{
  "status": "ok",
  "error": null,
  "data": {
    "host": "myspace.com",
    "has_spf_record": true,
    "dns_lookups_num": 9,
    "spf_record": "v=spf1 mx ip4:63.208.226.34 ip4:204.16.32.0/22 ip4:67.134.143.0/24 ip4:216.205.243.0/24 ip4:34.85.156.5/32 ip4:35.245.108.108/32 ip4:34.86.129.193/32 ip4:34.86.134.94/32 ip4:34.85.222.234/32 ip4:34.86.176.234/32 ip4:34.86.125.212/32 ip4:34.85.224.60/32 ip4:34.86.160.49/32 ip4:35.245.64.166/32 ip4:35.188.226.11/32 ip4:34.86.208.228/32 ip4:34.85.216.144/32 ip4:35.221.22.153/32 ip4:34.86.137.108/32 ip4:34.86.51.35/32 ip4:34.150.221.40/32 ip4:34.85.216.70/32 ip4:34.86.37.191/32 ip4:34.85.214.215/32 ip4:35.236.234.82/32 ip4:34.86.161.241/32 ip4:216.32.181.16 ip4:216.178.32.0/20 ip4:168.235.224.0/24 include:_netblocks.mimecast.com -all",
    "spf_records_list": [
      {
        "origin": "myspace.com",
        "record": "v=spf1 mx ip4:63.208.226.34 ip4:204.16.32.0/22 ip4:67.134.143.0/24 ip4:216.205.243.0/24 ip4:34.85.156.5/32 ip4:35.245.108.108/32 ip4:34.86.129.193/32 ip4:34.86.134.94/32 ip4:34.85.222.234/32 ip4:34.86.176.234/32 ip4:34.86.125.212/32 ip4:34.85.224.60/32 ip4:34.86.160.49/32 ip4:35.245.64.166/32 ip4:35.188.226.11/32 ip4:34.86.208.228/32 ip4:34.85.216.144/32 ip4:35.221.22.153/32 ip4:34.86.137.108/32 ip4:34.86.51.35/32 ip4:34.150.221.40/32 ip4:34.85.216.70/32 ip4:34.86.37.191/32 ip4:34.85.214.215/32 ip4:35.236.234.82/32 ip4:34.86.161.241/32 ip4:216.32.181.16 ip4:216.178.32.0/20 ip4:168.235.224.0/24 include:_netblocks.mimecast.com -all",
        "chars_num": 637,
        "use_macro": false,
        "domains": [
          "_netblocks.mimecast.com"
        ],
        "authorized_ips": {
          "ipv4": [
            "63.208.226.34",
            "204.16.32.0/22",
            "67.134.143.0/24",
            "216.205.243.0/24",
            "34.85.156.5/32",
            "35.245.108.108/32",
            "34.86.129.193/32",
            "34.86.134.94/32",
            "34.85.222.234/32",
            "34.86.176.234/32",
            "34.86.125.212/32",
            "34.85.224.60/32",
            "34.86.160.49/32",
            "35.245.64.166/32",
            "35.188.226.11/32",
            "34.86.208.228/32",
            "34.85.216.144/32",
            "35.221.22.153/32",
            "34.86.137.108/32",
            "34.86.51.35/32",
            "34.150.221.40/32",
            "34.85.216.70/32",
            "34.86.37.191/32",
            "34.85.214.215/32",
            "35.236.234.82/32",
            "34.86.161.241/32",
            "216.32.181.16",
            "216.178.32.0/20",
            "168.235.224.0/24"
          ]
        }
      },
      {
        "origin": "_netblocks.mimecast.com",
        "record": "v=spf1 include:eu._netblocks.mimecast.com include:us._netblocks.mimecast.com include:za._netblocks.mimecast.com include:de._netblocks.mimecast.com include:au._netblocks.mimecast.com include:ca._netblocks.mimecast.com include:usb._netblocks.mimecast.com ~all",
        "chars_num": 257,
        "use_macro": false,
        "domains": [
          "eu._netblocks.mimecast.com",
          "us._netblocks.mimecast.com",
          "za._netblocks.mimecast.com",
          "de._netblocks.mimecast.com",
          "au._netblocks.mimecast.com",
          "ca._netblocks.mimecast.com",
          "usb._netblocks.mimecast.com"
        ]
      },
      {
        "origin": "eu._netblocks.mimecast.com",
        "record": "v=spf1 ip4:195.130.217.0/24 ip4:91.220.42.0/24 ip4:146.101.78.0/24 ip4:207.82.80.0/24 ip4:213.167.81.0/25 ip4:193.7.207.0/25 ip4:213.167.75.0/25 ip4:185.58.85.0/24 ip4:185.58.86.0/24 ip4:193.7.206.0/25 ip4:147.28.36.0/24 ~all",
        "chars_num": 225,
        "use_macro": false,
        "authorized_ips": {
          "ipv4": [
            "195.130.217.0/24",
            "91.220.42.0/24",
            "146.101.78.0/24",
            "207.82.80.0/24",
            "213.167.81.0/25",
            "193.7.207.0/25",
            "213.167.75.0/25",
            "185.58.85.0/24",
            "185.58.86.0/24",
            "193.7.206.0/25",
            "147.28.36.0/24"
          ]
        }
      },
      {
        "origin": "us._netblocks.mimecast.com",
        "record": "v=spf1 ip4:207.211.31.0/25 ip4:205.139.110.0/24 ip4:216.205.24.0/24 ip4:170.10.129.0/24 ip4:63.128.21.0/24 ip4:170.10.133.0/24 ip4:185.58.84.93/32 ip4:207.211.41.113/32 ip4:207.211.30.64/26 ip4:207.211.30.128/25 ip4:216.145.221.0/24 ip4:170.10.128.0/24 ip4:170.10.132.56/29 ip4:170.10.132.64/29 ~all",
        "chars_num": 299,
        "use_macro": false,
        "authorized_ips": {
          "ipv4": [
            "207.211.31.0/25",
            "205.139.110.0/24",
            "216.205.24.0/24",
            "170.10.129.0/24",
            "63.128.21.0/24",
            "170.10.133.0/24",
            "185.58.84.93/32",
            "207.211.41.113/32",
            "207.211.30.64/26",
            "207.211.30.128/25",
            "216.145.221.0/24",
            "170.10.128.0/24",
            "170.10.132.56/29",
            "170.10.132.64/29"
          ]
        }
      },
      {
        "origin": "za._netblocks.mimecast.com",
        "record": "v=spf1 ip4:41.74.192.0/22 ip4:41.74.200.0/23 ip4:41.74.196.0/22 ip4:41.74.204.0/23 ip4:41.74.206.0/24 ~all",
        "chars_num": 106,
        "use_macro": false,
        "authorized_ips": {
          "ipv4": [
            "41.74.192.0/22",
            "41.74.200.0/23",
            "41.74.196.0/22",
            "41.74.204.0/23",
            "41.74.206.0/24"
          ]
        }
      },
      {
        "origin": "de._netblocks.mimecast.com",
        "record": "v=spf1 ip4:51.163.158.0/24 ip4:194.104.109.0/24 ip4:194.104.111.0/24 ip4:194.104.110.21/32 ip4:194.104.110.240/28 ip4:62.140.10.21/32 ip4:62.140.7.0/24 ip4:194.104.108.240/29 ip4:194.104.108.21/32 ip4:51.163.159.0/24 ~all",
        "chars_num": 221,
        "use_macro": false,
        "authorized_ips": {
          "ipv4": [
            "51.163.158.0/24",
            "194.104.109.0/24",
            "194.104.111.0/24",
            "194.104.110.21/32",
            "194.104.110.240/28",
            "62.140.10.21/32",
            "62.140.7.0/24",
            "194.104.108.240/29",
            "194.104.108.21/32",
            "51.163.159.0/24"
          ]
        }
      },
      {
        "origin": "au._netblocks.mimecast.com",
        "record": "v=spf1 ip4:103.13.69.0/24 ip4:124.47.150.0/24 ip4:124.47.189.0/24 ip4:103.96.23.0/24 ip4:103.96.21.0/24 ip4:180.189.28.0/24 ip4:216.145.217.0/24 ip4:103.96.22.96/28 ip4:103.96.22.22/32 ip4:103.96.20.22/32 ip4:103.96.20.96/28 ~all",
        "chars_num": 229,
        "use_macro": false,
        "authorized_ips": {
          "ipv4": [
            "103.13.69.0/24",
            "124.47.150.0/24",
            "124.47.189.0/24",
            "103.96.23.0/24",
            "103.96.21.0/24",
            "180.189.28.0/24",
            "216.145.217.0/24",
            "103.96.22.96/28",
            "103.96.22.22/32",
            "103.96.20.22/32",
            "103.96.20.96/28"
          ]
        }
      },
      {
        "origin": "ca._netblocks.mimecast.com",
        "record": "v=spf1 ip4:170.10.145.0/24 ip4:170.10.147.0/24 ip4:170.10.144.126/32 ip4:170.10.146.126/32 ip4:170.10.144.240/29 ip4:170.10.146.240/29 ip4:216.145.216.0/24 ~all",
        "chars_num": 160,
        "use_macro": false,
        "authorized_ips": {
          "ipv4": [
            "170.10.145.0/24",
            "170.10.147.0/24",
            "170.10.144.126/32",
            "170.10.146.126/32",
            "170.10.144.240/29",
            "170.10.146.240/29",
            "216.145.216.0/24"
          ]
        }
      },
      {
        "origin": "usb._netblocks.mimecast.com",
        "record": "v=spf1 ip4:170.10.151.0/24 ip4:170.10.153.0/24 ip4:170.10.150.240/29 ip4:170.10.152.240/29 ip4:170.10.156.0/24 ip4:170.10.157.0/24 ~all",
        "chars_num": 135,
        "use_macro": false,
        "authorized_ips": {
          "ipv4": [
            "170.10.151.0/24",
            "170.10.153.0/24",
            "170.10.150.240/29",
            "170.10.152.240/29",
            "170.10.156.0/24",
            "170.10.157.0/24"
          ]
        }
      }
    ],
    "domains_extracted": [
      "myspace.com",
      "_netblocks.mimecast.com",
      "eu._netblocks.mimecast.com",
      "us._netblocks.mimecast.com",
      "za._netblocks.mimecast.com",
      "de._netblocks.mimecast.com",
      "au._netblocks.mimecast.com",
      "ca._netblocks.mimecast.com",
      "usb._netblocks.mimecast.com"
    ],
    "authorized_ips": {
      "ipv4": [
        "63.208.226.34",
        "204.16.32.0/22",
        "67.134.143.0/24",
        "216.205.243.0/24",
        "34.85.156.5/32",
        "35.245.108.108/32",
        "34.86.129.193/32",
        "34.86.134.94/32",
        "34.85.222.234/32",
        "34.86.176.234/32",
        "34.86.125.212/32",
        "34.85.224.60/32",
        "34.86.160.49/32",
        "35.245.64.166/32",
        "35.188.226.11/32",
        "34.86.208.228/32",
        "34.85.216.144/32",
        "35.221.22.153/32",
        "34.86.137.108/32",
        "34.86.51.35/32",
        "34.150.221.40/32",
        "34.85.216.70/32",
        "34.86.37.191/32",
        "34.85.214.215/32",
        "35.236.234.82/32",
        "34.86.161.241/32",
        "216.32.181.16",
        "216.178.32.0/20",
        "168.235.224.0/24",
        "195.130.217.0/24",
        "91.220.42.0/24",
        "146.101.78.0/24",
        "207.82.80.0/24",
        "213.167.81.0/25",
        "193.7.207.0/25",
        "213.167.75.0/25",
        "185.58.85.0/24",
        "185.58.86.0/24",
        "193.7.206.0/25",
        "147.28.36.0/24",
        "207.211.31.0/25",
        "205.139.110.0/24",
        "216.205.24.0/24",
        "170.10.129.0/24",
        "63.128.21.0/24",
        "170.10.133.0/24",
        "185.58.84.93/32",
        "207.211.41.113/32",
        "207.211.30.64/26",
        "207.211.30.128/25",
        "216.145.221.0/24",
        "170.10.128.0/24",
        "170.10.132.56/29",
        "170.10.132.64/29",
        "41.74.192.0/22",
        "41.74.200.0/23",
        "41.74.196.0/22",
        "41.74.204.0/23",
        "41.74.206.0/24",
        "51.163.158.0/24",
        "194.104.109.0/24",
        "194.104.111.0/24",
        "194.104.110.21/32",
        "194.104.110.240/28",
        "62.140.10.21/32",
        "62.140.7.0/24",
        "194.104.108.240/29",
        "194.104.108.21/32",
        "51.163.159.0/24",
        "103.13.69.0/24",
        "124.47.150.0/24",
        "124.47.189.0/24",
        "103.96.23.0/24",
        "103.96.21.0/24",
        "180.189.28.0/24",
        "216.145.217.0/24",
        "103.96.22.96/28",
        "103.96.22.22/32",
        "103.96.20.22/32",
        "103.96.20.96/28",
        "170.10.145.0/24",
        "170.10.147.0/24",
        "170.10.144.126/32",
        "170.10.146.126/32",
        "170.10.144.240/29",
        "170.10.146.240/29",
        "216.145.216.0/24",
        "170.10.151.0/24",
        "170.10.153.0/24",
        "170.10.150.240/29",
        "170.10.152.240/29",
        "170.10.156.0/24",
        "170.10.157.0/24"
      ],
      "ipv6": []
    },
    "issues_found": [],
    "spf_valid": true,
    "has_issues": false,
    "macros_found": false,
    "ip_pass": false,
    "elapsed_ms": 431,
    "all_qualifier": "fail",
    "risk_score": 5,
    "risk_level": "low"
  }
}

Response fields

Paths are relative to data. Premium fields are absent rather than zeroed on plans that do not include them, so check for presence instead of comparing to 0.

FieldTypeExampleDescription
hoststring"myspace.com"The domain name being validated
has_spf_recordbooleantrueWhether the domain has SPF record
dns_lookups_numPremiumnumber9Total number of DNS lookups performed
spf_recordstring"v=spf1 mx ip4:63.208.226.34 ip4:204.16.32.0/22 ip4:67.134.143.0/24 ip4:216.205.243.0/24 ip4:34.85.156.5/32 ip4:35.245.108.108/32 ip4:34.86.129.193/32 ip4:34.86.134.94/32 ip4:34.85.222.234/32 ip4:34.86.176.234/32 ip4:34.86.125.212/32 ip4:34.85.224.60/32 ip4:34.86.160.49/32 ip4:35.245.64.166/32 ip4:35.188.226.11/32 ip4:34.86.208.228/32 ip4:34.85.216.144/32 ip4:35.221.22.153/32 ip4:34.86.137.108/32 ip4:34.86.51.35/32 ip4:34.150.221.40/32 ip4:34.85.216.70/32 ip4:34.86.37.191/32 ip4:34.85.214.215/32 ip4:35.236.234.82/32 ip4:34.86.161.241/32 ip4:216.32.181.16 ip4:216.178.32.0/20 ip4:168.235.224.0/24 include:_netblocks.mimecast.com -all"The complete SPF record string
spf_records_listPremiumarray[9]List of SPF records with detailed parsing
originPremiumstring"myspace.com"Domain origin of SPF record
recordPremiumstring"v=spf1 mx ip4:63.208.226.34 ip4:204.16.32.0/22 ip4:67.134.143.0/24 ip4:216.205.243.0/24 ip4:34.85.156.5/32 ip4:35.245.108.108/32 ip4:34.86.129.193/32 ip4:34.86.134.94/32 ip4:34.85.222.234/32 ip4:34.86.176.234/32 ip4:34.86.125.212/32 ip4:34.85.224.60/32 ip4:34.86.160.49/32 ip4:35.245.64.166/32 ip4:35.188.226.11/32 ip4:34.86.208.228/32 ip4:34.85.216.144/32 ip4:35.221.22.153/32 ip4:34.86.137.108/32 ip4:34.86.51.35/32 ip4:34.150.221.40/32 ip4:34.85.216.70/32 ip4:34.86.37.191/32 ip4:34.85.214.215/32 ip4:35.236.234.82/32 ip4:34.86.161.241/32 ip4:216.32.181.16 ip4:216.178.32.0/20 ip4:168.235.224.0/24 include:_netblocks.mimecast.com -all"Full SPF record content
chars_numPremiumnumber637Character count of SPF record
use_macroPremiumbooleanfalseWhether record uses macros
domainsPremiumarray[_netblocks.mimecast.com]Domains referenced in SPF record
authorized_ipsPremiumobject{...}All IP addresses authorized by SPF
ipv4Premiumarray[63.208.226.34, ...]IPv4 addresses authorized to send mail
domains_extractedPremiumarray[myspace.com, ...]All domains found in SPF chain
authorized_ipsPremiumobject{...}All IP addresses authorized by SPF
ipv4Premiumarray[63.208.226.34, ...]All IPv4 addresses authorized by SPF
ipv6Premiumarray[]All IPv6 addresses authorized by SPF
issues_foundPremiumarray[]List of SPF validation issues
spf_validbooleantrueWhether SPF record is valid
has_issuesbooleanfalseWhether validation found issues
macros_foundPremiumbooleanfalseWhether SPF record uses macros
ip_passbooleanfalseWhether IP passes SPF check
elapsed_msPremiumnumber431Validation processing time in milliseconds
all_qualifierstring"fail"The qualifier on the SPF 'all' mechanism: fail (-all, strict), softfail (~all), neutral (?all) or pass (+all, authorizes any sender). Null when the record has no all mechanism (e.g. defers via redirect)
risk_scorePremiumnumber5Composite 0-100 email-spoofing risk based on the SPF enforcement qualifier and DNS-lookup limit — higher means the domain is more easily spoofed (no SPF or +all scores high; -all scores low)
risk_levelPremiumstring"low"Risk band derived from the score: low, medium or high

Errors

Read the HTTP status first, then error for the specific reason. The body names the parameter that has to change. Error handling covers the full status list and which of them are worth retrying.

StatusMeaningWhat to do
400Input was rejectedRead error; it names the parameter.
401Key missing or invalidCheck the header name and the key value.
403Key valid, but not permittedA key restriction or IP allow-list; see key scoping.
429Rate limited, or out of creditsRead error to tell them apart; see rate limits.

Other ways to use SPF Validator

Set up SPF Validator on APIVerve, or reach the same source a different way. Your APIVerve account and credits work on all of them — one key, one balance.

Give it to an AI agentConnect over MCP and your agent calls it as a native tool — Claude, Cursor, ChatGPT.VerveKitReference →
Use it in Google Sheets or ExcelA =VERVE() formula fills a column — no script, no export, recalculates in place.VerveSheetsReference →
Ground an agent on itA cited, machine-checkable fact your model can't produce on its own.VerveContextReference →

More in Domain Data:

Was this page helpful?