With the SPF lookup you analyze the SPF record of a domain for errors, security risks and authorized IP addresses. Optionally, you can specify an IP address to check if it is authorized to send e-mail on behalf of the domain. The SPF lookup analyzes registered TXT records in real time. If you want to specify an SPF record manually, use the SPF Analyzer.
Does a valid SPF record exist?
An SPF record was found for the domain itk-droege.de.
The SPF record for itk-droege.de is valid.
The syntax check of the SPF record shows no obvious errors.
Which IP-s are legitimate to send emails?
The SPF record contains a reference to external rules, which means that the validity of the SPF record depends on at least one other domain. A detailed list of the rules used externally can be found in the analysis result.
In total, 32 IP address(es) were authorized by the SPF record to send emails.
The SPF record analysis was performed on 27.12.2024 at 07:21:40 clock.
(itk-droege.de → itk-droege.de.spf.hornetdmarc.com → spf.hornetsecurity.com) Mechanisms of SPF-Record are valid
OK for 'v' -> 'spf1'
OK for 'ip4' -> '199.27.221.76'
OK for 'ip4' -> '174.142.136.160/27'
OK for 'ip4' -> '92.54.27.0/24'
OK for 'ip4' -> '52.62.125.178'
OK for 'ip4' -> '52.62.114.130'
OK for 'ip4' -> '199.27.221.82'
OK for 'ip4' -> '199.27.221.81'
OK for 'ip4' -> '216.46.11.244'
OK for 'ip4' -> '216.46.11.238'
OK for 'ip4' -> '193.135.100.0/27'
OK for 'ip4' -> '83.246.65.0/24'
OK for 'ip4' -> '108.163.133.224/27'
OK for 'ip4' -> '209.172.38.64/27'
OK for 'ip4' -> '129.232.203.80/28'
OK for 'ip4' -> '52.62.108.212/32'
OK for 'ip4' -> '52.62.123.207/32'
OK for 'ip4' -> '173.45.18.0/24'
OK for 'ip4' -> '81.20.94.0/24'
OK for 'ip4' -> '94.100.128.0/20'
OK for 'ip4' -> '185.140.204.0/22'
OK for 'all' -> '~'
|
(itk-droege.de → itk-droege.de.spf.hornetdmarc.com → spf.hornetsecurity.com) The SPF consists of a permissible character set.
The SPF record of spf.hornetsecurity.com contains valid characters.
|
(itk-droege.de → itk-droege.de.spf.hornetdmarc.com → spf.protection.outlook.com) Mechanisms of SPF-Record are valid
OK for 'v' -> 'spf1'
OK for 'ip4' -> '40.92.0.0/15'
OK for 'ip4' -> '40.107.0.0/16'
OK for 'ip4' -> '52.100.0.0/15'
OK for 'ip4' -> '52.102.0.0/16'
OK for 'ip4' -> '52.103.0.0/17'
OK for 'ip4' -> '104.47.0.0/17'
OK for 'ip6' -> '2a01:111:f400::/48'
OK for 'ip6' -> '2a01:111:f403::/49'
OK for 'ip6' -> '2a01:111:f403:8000::/51'
OK for 'ip6' -> '2a01:111:f403:c000::/51'
OK for 'ip6' -> '2a01:111:f403:f000::/52'
OK for 'all' -> '-'
|
(itk-droege.de → itk-droege.de.spf.hornetdmarc.com → spf.protection.outlook.com) The SPF consists of a permissible character set.
The SPF record of spf.protection.outlook.com contains valid characters.
|
(itk-droege.de → itk-droege.de.spf.hornetdmarc.com) Mechanisms of SPF-Record are valid
OK for 'v' -> 'spf1'
OK for 'ip4' -> '152.53.85.13'
OK for 'include' -> 'spf.protection.outlook.com'
OK for 'include' -> 'spf.hornetsecurity.com'
OK for 'all' -> '~'
|
(itk-droege.de → itk-droege.de.spf.hornetdmarc.com) The SPF consists of a permissible character set.
The SPF record of itk-droege.de.spf.hornetdmarc.com contains valid characters.
|
(itk-droege.de) Mechanisms of SPF-Record are valid
OK for 'v' -> 'spf1'
OK for 'redirect' -> 'itk-droege.de.spf.hornetdmarc.com'
|
(itk-droege.de) The DNS lookup limit was not exceeded.
The limit was not exceeded:
1: itk-droege.de include:itk-droege.de.spf.hornetdmarc.com 2: itk-droege.de include:itk-droege.de.spf.hornetdmarc.com include:spf.protection.outlook.com 3: itk-droege.de include:itk-droege.de.spf.hornetdmarc.com include:spf.hornetsecurity.com |
(itk-droege.de) The SPF consists of a permissible character set.
The SPF record of itk-droege.de contains valid characters.
|
SPF record available?
We found an SPF record for the domain.
Will be forwarded to another SPF record?
There is an SPF record that refers to another SPF record Additional entries in this record are therefore ignored.
Are the server addresses allowed to send e-mails?
In the SPF entry the mechanism 'a' has not been set.
Additionally authorized A-records?
In addition to the A-Records stored in the DNS, we could not find any other records authorized in the SPF-Record.
Are the registered mail servers allowed to send e-mails?
In the SPF entry the mechanism 'mx' has not been set
Additionally authorized MX records
We could not find any other records authorized in the SPF record besides the MX records stored in the DNS
Additionally authorized IPv4 addresses
No explicit IPv4 addresses in the SPF record have been authorised to send
Additionally authorized IPv6 addresses
No explicit IPv6 addresses in the SPF record have been authorised to send
Additional external SPF records
We could not find any other records authorized in SPF-Record
How is the sender informed?
The exp mechanism acts as a return to the sender if the IP address was not authorized to send and notify them. None was found.
PTR (obsolete mechanism)
The ptr mechanism is deprecated, slow and insecure and should not be used
PTR:
The ptr mechanism is deprecated, slow and insecure and should not be used
Authorize IP addresses with markers
When SPF is evaluated, macros can specifically authorize Ip addresses based on the request or connection of the user or client (RFC7208 )
E-Mail handling
How should the checkHost() function of the e-mail server handle the e-mail? (syntax )
Receiver address
analysis.ra-missing
Amount of reports
analysis.rp-missing
Report selection
analysis.rr-missing
Unknown mechanisms
No unknown mechanisms were found in the SPF record.
Server IP Address
We have determined the following IP address for the domain:
No domain specified
Reverse address
We have determined the following name for the server IP address:
v2.kundenserver.xyz
Get a first impression of the risk potential in your company