What does this SPF checker test for cold email?
Four things, in the order a receiving server meets them. It looks for a TXT record at the root of the domain starting v=spf1, and fails if there are none or more than one, because two SPF records are a permanent error. It reads how the record ends (~all, -all, or the dangerous +all). Then it follows every include: and redirect= and counts DNS lookups, because SPF stops working past 10.
What is the SPF 10-lookup limit in cold email?
SPF allows at most 10 DNS lookups to evaluate a record, counting every include, a, mx, ptr, exists and redirect, including the ones nested inside each include. Past 10 the receiver returns a permanent error and SPF fails, even though every sender is listed. Main domains hit this after years of adding tools. A sending domain used only for cold email usually needs one include, for its mailbox host, which is one reason to keep cold email off your main domain. Our SPF record guide explains each mechanism.
Should a cold email domain use ~all or -all?
Either passes. ~all (softfail) asks receivers to treat unlisted senders as suspicious; -all (fail) asks them to reject. With DMARC in place, receivers act on DMARC rather than the SPF ending, so ~all is the common, safe choice while you set up. Never use +all: it authorises every server on the internet to send as you.
My SPF passes, so why does my cold email still fail DMARC?
Because DMARC needs the SPF domain to match the domain in your From line. Many sending tools send with their own return-path domain, so SPF passes for them and not for you. DKIM signed with your domain fixes it. Check the other records with the full domain checker, and see fixing DMARC fail for alignment. Need a new record? The SPF record generator builds one.