How-to
Find unused and missing SPF entries
The SPF IP usage panel compares what your SPF record authorises with what actually sends, so you can prune dead entries and catch unauthorised senders.
Jump to section
SPF allows at most 10 DNS lookups. Every include: in your record spends
one, and most organisations accumulate includes for services they stopped
using years ago. The SPF IP usage panel on each domain's page shows
which authorised addresses actually send mail, so you can reclaim lookups
safely.
Where to find it
Open the domain from Domains, then choose SPF IP usage in the
side menu. The panel resolves every include: in your published SPF
record down to its literal IP addresses and ranges, then checks each one
against the sending sources in your DMARC report data for the selected
window.
Reading the four numbers
- IPs in SPF — every address or range your record authorises after resolving all includes.
- Active — authorised entries that were seen sending in the window, with message volume and sender counts per entry.
- Unused — authorised entries with no observed sending. These are candidates for removal, but check with the provider first: low-volume or seasonal senders may simply not have sent recently. Pick a window long enough to cover your quietest sender.
- Missing from SPF — addresses sending your mail that your record does not authorise, shown with the detected service where we can identify one. Each is either a legitimate service to add or a spoofer your DMARC policy should be blocking.
A source only appears under "missing" when it fails SPF more often than it passes — senders that authenticate through a subdomain's own SPF record are not flagged.
Acting on it
Remove an unused include: at your DNS host, then use SPF
flattening on the same page to confirm the lookup count dropped. For
missing senders that are legitimate, the Provider setup panel lists
the exact records each detected service expects.