Skip to content

TXT record lookup

Enter a domain to see every TXT record it publishes, including SPF, verification tokens, DKIM keys, and DMARC policies. The result compares four public resolvers with the domain's own nameserver and flags duplicate SPF records.

What a TXT record is

A TXT record holds free-form text. DNS itself does not interpret it. The services that read it do. Most TXT records on a typical domain do one of four jobs: SPF lists the servers allowed to send mail as your domain, DKIM publishes the public key receivers use to check message signatures, DMARC tells receivers what to do with mail that fails those checks, and verification tokens prove to a service that you control the domain. One name can hold many TXT records side by side.

Each string inside a TXT record can be at most 255 characters (RFC 1035). Longer values, such as 2048-bit DKIM keys, are stored as several strings in one record, and readers join them together without adding spaces. The location matters too. SPF and verification tokens usually sit on the bare domain, DMARC lives at _dmarc.example.com, and DKIM keys live at selector._domainkey.example.com. A lookup of example.com alone does not show the last two.

Example TXT records

  • example.com. 3600 IN TXT "v=spf1 include:_spf.google.com ~all"

    SPF: Google's mail servers may send for this domain, and mail from anywhere else should be treated as suspicious (softfail).

  • _dmarc.example.com. 3600 IN TXT "v=DMARC1; p=quarantine; rua=mailto:[email protected]"

    DMARC: mail that fails authentication should go to spam, and daily aggregate reports go to the listed address.

  • google._domainkey.example.com. 3600 IN TXT "v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOC..."

    DKIM: the public key for selector "google", which receivers use to verify signed messages (key shortened here).

How to read your result

Several records is normal
Each line in a resolver's row is a separate TXT record. A domain often has an SPF record plus several verification tokens. What matters is the content: exactly one record starting with v=spf1, and no leftovers you do not recognize.
Split strings are shown joined
Long records stored as several 255-character strings are shown as one continuous value, the way mail receivers read them. If a DKIM key shows a stray space or quote mark in the middle, the record was split or pasted incorrectly.
Enter the right name for DKIM and DMARC
To check DMARC, enter _dmarc.example.com. To check DKIM, enter selector._domainkey.example.com, using the selector your mail provider gave you. Some providers publish DKIM as a CNAME to their own key instead, in which case the CNAME lookup shows it.
The duplicate SPF warning
If more than one record starts with v=spf1, the result flags it. Receivers do not pick one: under RFC 7208 the whole SPF check returns an error, so neither record protects the domain.

Common TXT record problems

Two SPF records
Setting up a new email or newsletter service often means adding a second v=spf1 record instead of extending the first. Merge them into one: keep a single v=spf1 at the start, combine the include: terms, and end with one all mechanism.
SPF over the 10-lookup limit
SPF allows at most 10 DNS lookups per check, counting include, a, mx, ptr, exists, and redirect, plus every lookup inside the included records. Going over makes the result a permanent error. Remove services you no longer use, drop ptr (RFC 7208 says not to use it), and replace a or mx with fixed IP ranges where that is practical.
Extra or escaped quotes
Many control panels add the surrounding quotes themselves. Pasting a value that already has quotes can store the quote marks inside the text, and the record stops matching what receivers expect. Paste the bare value and check the lookup.
Broken DKIM key
Long keys get cut off by panels with a length limit, or pick up spaces and line breaks when copied. If signatures fail, compare the key in the lookup character for character with the one your provider shows, and use the panel's long-record support or the provider's CNAME setup.
DMARC at the wrong name or duplicated
A DMARC record placed on the bare domain is ignored, because receivers only look at _dmarc.example.com. Two DMARC records at that name are also ignored. Keep exactly one, at the _dmarc name.

Other record lookups

Frequently asked questions

How do I check the TXT records for a domain?

Enter the domain above with TXT selected. Every TXT record the resolvers return is listed, along with the answer from the domain's own nameserver and the record's TTL.

Can a domain have more than one TXT record?

Yes, as many as it needs, and verification tokens commonly pile up over time. The limits are on specific kinds: only one SPF record per name and only one DMARC record at _dmarc.

How do I check my DMARC record?

Enter _dmarc.yourdomain.com with TXT selected. The record should start with v=DMARC1 and include a p= policy of none, quarantine, or reject. If nothing comes back, the domain has no DMARC policy.

What is the maximum length of a TXT record?

Each string inside the record is limited to 255 characters, but one record can contain several strings that are joined when read. That is how long DKIM keys fit. Very large TXT sets make DNS responses bigger, which can force resolvers to retry over TCP, so remove tokens you no longer need.

What is the difference between ~all and -all in SPF?

Both end the SPF record and cover all senders not listed. ~all (softfail) asks receivers to treat unlisted senders as suspicious, while -all (fail) says they are not authorized at all. Receivers combine either result with DMARC and their own filtering.