---
title: "The dig Command Cheat Sheet: How to Query SPF Records Like a Security Pro | AutoSPF"
description: "Learn how to use the dig command to query SPF records, troubleshoot DNS issues, check the 10-lookup limit, and strengthen email security."
image: "https://autospf.com/og/blog/dig-command-cheat-sheet-query-spf-records-like-security-pro.png"
canonical: "https://autospf.com/blog/dig-command-cheat-sheet-query-spf-records-like-security-pro/"
---

Quick Answer

The dig command helps query and troubleshoot SPF records through DNS. Use it to inspect SPF, DKIM, and DMARC records, trace DNS lookups, identify the 10-lookup limit, and detect configuration issues that can affect email delivery and security.

Share 

[ ](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Fautospf.com%2Fblog%2Fdig-command-cheat-sheet-query-spf-records-like-security-pro%2F "Share on LinkedIn") [ ](https://twitter.com/intent/tweet?text=The%20dig%20Command%20Cheat%20Sheet%3A%20How%20to%20Query%20SPF%20Records%20Like%20a%20Security%20Pro&url=https%3A%2F%2Fautospf.com%2Fblog%2Fdig-command-cheat-sheet-query-spf-records-like-security-pro%2F "Share on X/Twitter") [ ](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fautospf.com%2Fblog%2Fdig-command-cheat-sheet-query-spf-records-like-security-pro%2F "Share on Facebook") [ ](https://reddit.com/submit?url=https%3A%2F%2Fautospf.com%2Fblog%2Fdig-command-cheat-sheet-query-spf-records-like-security-pro%2F&title=The%20dig%20Command%20Cheat%20Sheet%3A%20How%20to%20Query%20SPF%20Records%20Like%20a%20Security%20Pro "Share on Reddit") [ ](mailto:?subject=The%20dig%20Command%20Cheat%20Sheet%3A%20How%20to%20Query%20SPF%20Records%20Like%20a%20Security%20Pro&body=Check out this article: https%3A%2F%2Fautospf.com%2Fblog%2Fdig-command-cheat-sheet-query-spf-records-like-security-pro%2F "Share via Email") 

![SPF Verification Workflow Guide](https://media.mailhop.org/autospf/spf-lookup-7770-1791457264204.jpg) 

Here’s something most IT pros don’t realize until it’s too late: that little dig TXT command you run to check an SPF record? It only shows you one-third of your **email security picture**. And according to [NSF-funded research](https://par.nsf.gov/servlets/purl/10327874), even perfectly configured SPF records can break legitimate emails when forwarding gets involved.

I’ve spent years helping organizations troubleshoot email delivery nightmares, and the pattern is always the same: someone assumes their [SPF record](https://autospf.com/blog/what-spf-records-are-and-how-they-protect-email-domains/) is “fine” because it exists. Then invoices go missing, legal notices bounce, and suddenly a DNS misconfiguration becomes a business crisis.

This guide will teach you not just how to dig SPF records, but how to actually understand what you’re looking at—and catch problems before they catch you.

_TL;DR: Use dig TXT domain.com +short to query SPF records, but always check DMARC too (dig TXT \_dmarc.domain.com). SPF alone isn’t enough—the UK government protects all .gov.uk domains with the full SPF/DKIM/DMARC triad. Watch for the 10-DNS-lookup limit, and remember that strict SPF policies (-all) can break email forwarding._

## Key Takeaways

- **SPF is one-third of email security**—always pair it with **DKIM and DMARC** for real protection
- **The 10-lookup limit is real**—complex SPF records with multiple include: statements can silently fail
- **Forwarding breaks SPF**—academic research confirms this fundamental limitation
- **Non-mail domains need SPF too**—use `v=spf1` `-all` to **prevent spoofing** of [parked domains](https://securityscorecard.com/blog/what-is-a-parked-domain/)
- **Government implementations set the bar**—the [UK’s Active Cyber Defence program](https://technologymagazine.com/news/what-does-the-uks-new-cyber-defence-programme-mean) shows what comprehensive protection looks like

## What Exactly Is an SPF Record (And Why Should You Care)?

SPF (Sender Policy Framework) is essentially a whitelist stored in your DNS. It tells receiving [mail servers](https://www.cloudflare.com/learning/email-security/what-is-a-mail-server/): “Here are the **IP addresses** authorized to send email on behalf of my domain.” When someone tries to send email claiming to be from your domain, the receiving server checks this list.

According to the [USPTO’s DNS documentation](https://ptacts.uspto.gov/ptacts/public-informations/petitions/1556023/download-documents?artifactId=hNYJFPaEzScr5f170uAD4ly1MZtTmqWOz4NlUx5HVLwJIH-oOqg5K0), SPF records live as [TXT records](https://www.digicert.com/faq/dns/what-is-a-txt-record) in the same system that resolves domain names to IP addresses. This matters because it means SPF inherits all of DNS’s quirks: propagation delays, [caching issues](https://support.beyond-sw.com/hc/en-us/articles/25613561201682-Identify-and-fix-caching-problems#%E2%80%98h%5F01JQB8WYSYBA2VB5BWM0A34XGQ%E2%80%99), and character limits.

The basic dig command couldn’t be simpler:

```
dig TXT example.com +short
```

But understanding the output? That’s where things get interesting.

## Anatomy of an SPF Record: Decoding What You See

Here’s a real-world SPF record you might encounter:

```
"v=spf1 include:_spf.google.com include:servers.mcsv.net ip4:192.168.1.0/24 -all"
```

![Spf Record Checker 2220](https://media.mailhop.org/autospf/spf-record-checker-2220-1791460160245.jpg) _SPF Record Components Explained — Source: RFC 7208_

Each component serves a specific purpose. The `v=spf1` declares the version. The `include:` statements pull in another **domain’s authorized servers** (useful when you use Google Workspace or Mailchimp). The `ip4:` directly authorizes specific IP ranges. And that `-all` at the end? That’s your enforcement policy—and it’s where most organizations get into trouble.

### The All-Important ‘All’ Mechanism

The ending mechanism determines what happens to emails that don’t match any authorized source:

![Spf Flattening 5467](https://media.mailhop.org/autospf/spf-flattening-5467-1791460508494.jpg)

_SPF ‘All’ Mechanisms: From Permissive to Strict — Source: RFC 7208_

Notice the spectrum from permissive to strict. Organizations often start with `~all` (soft fail) during testing, then forget to switch to `-all` (hard fail) for production. This leaves a security gap that attackers happily exploit.

## Why SPF Alone Is Security Theater

Here’s the uncomfortable truth the [UK’s National Cyber Security Centre](https://www.ncsc.gov.uk/files/Active-Cyber-Defence-ACD-The-Fourth-Year.pdf) discovered: SPF by itself is insufficient. Their Active Cyber Defence program implements SPF as “one of three core email authentication controls alongside DKIM and DMARC.”![Spf Lookup 1200](https://media.mailhop.org/autospf/spf-lookup-1200-1791460277167.jpg) _The Email Authentication Triad — Source: NCSC UK Active Cyber Defence (2021)_

Think of it like a [three-factor authentication](https://www.techtarget.com/cybersecurity/definition/three-factor-authentication-3FA) system for email. **SPF verifies** the sending server’s IP is authorized. DKIM cryptographically signs the message content. _DMARC ties them together and tells receivers what to do when checks fail. Skip any one, and you’ve left a door open._

### The Complete Verification Workflow

When you’re auditing a domain’s email security, run all three checks:

`dig TXT example.com +short` — SPF record`dig TXT _dmarc.example.com +short` — DMARC policy`dig TXT selector.`\_domainkey.example.com +short\` — DKIM key

A domain with a perfect SPF record but no **DMARC policy** is like having a fancy lock on your front door while leaving the back door wide open.

## The 10-Lookup Limit: The Silent SPF Killer

This is where even experienced admins get burned. RFC 7208 limits SPF to 10 [DNS lookups](https://threat.media/definition/what-is-a-dns-lookup/). Every `include:`, `a:`, `mx:`, and `redirect=` counts. Exceed the limit, and your entire SPF record fails validation—silently.![Spf Record Example 3700](https://media.mailhop.org/autospf/spf-record-example-3700-1791460213268.jpg) _How Services Consume Your SPF Lookup Budget — Source: RFC 7208 Specification_

Modern organizations easily hit this limit. You use [Google Workspace](https://en.wikipedia.org/wiki/Google%5FWorkspace) (1-3 lookups), Mailchimp (1-2 lookups), Salesforce (1-2 lookups), your ticketing system (1-2 lookups), and suddenly you’re at **8 lookups** before adding your own mail servers. The nested includes within those services can push you over.

### How to Count Your Lookups

Trace each include manually:

`dig TXT example.com +short` — Main record`dig TXT _spf.google.com +short` — First include (check for nested includes)d`ig TXT _netblocks.google.com +short` — Nested include

_Or save yourself the headache and use an online SPF validator. But knowing how to trace manually helps when you’re troubleshooting at 2 AM._ ![Spf Record Checker 6660](https://media.mailhop.org/autospf/spf-record-checker-6660-1791460700591.jpg) _The SPF Lookup Limit — Source: RFC 7208 Specification_

## When Good SPF Goes Bad: The Forwarding Problem

Here’s a scenario that trips up countless organizations: You **implement strict SPF** with `-all`. Your security team celebrates. Then your [CEO’s assistant](https://ca.indeed.com/career-advice/finding-a-job/assistant-to-ceo) reports that emails forwarded to her personal Gmail aren’t arriving.

The [NSF research paper](https://par.nsf.gov/servlets/purl/10327874) on email forwarding confirms this isn’t a bug—it’s a fundamental design limitation. When email gets forwarded, the forwarding server’s IP becomes the apparent sender. That IP isn’t in your SPF record. Authentication fails.![Spf Lookup 8880](https://media.mailhop.org/autospf/spf-lookup-8880-1791460749321.jpg) _Email Authentication Fate: Direct vs Forwarded — Source: NSF Email Forwarding Research (2022)_

**This creates an impossible choice:** strict SPF enforcement for security, or permissive policies for compatibility. Technologies like ARC (Authenticated Received Chain) and [SRS (Sender Rewriting Scheme)](https://www.xeams.com/sender-rewriting-schema-srs.htm) help, but adoption remains inconsistent.

### Diagnosing Forwarding Failures

When emails fail after forwarding:

1. Check the [bounced email’s](https://www.activecampaign.com/glossary/bounced-email) headers for the connecting IP
2. Run `dig TXT senderdomain.com +short` on the original sender
3. Verify whether that forwarding server IP appears in the SPF record (it won’t)
4. Look for ARC headers indicating the forwarding chain was preserved

## Government-Scale Implementation: Learning from the UK

The UK’s Active Cyber Defence program provides a masterclass in comprehensive [email security](https://autospf.com/). They didn’t just implement SPF for active mail domains—they protected _all_ \*.gov.uk domains, including those that never send email.![Spf Flattening 9990](https://media.mailhop.org/autospf/spf-flattening-9990-1791461035065.jpg) _UK Government Email Security Coverage — Source: NCSC UK Active Cyber Defence (2021)_

Why **protect non-mail domains**? Because attackers love spoofing legitimate-sounding subdomains. An email from [benefits-help@support.gov.uk](mailto:benefits-help@support.gov.uk) looks convincing, even if that subdomain doesn’t exist. A null SPF record (`v=spf1 -all`) explicitly declares no servers are authorized, killing these attacks.

### The Null SPF Strategy

For every domain you own that doesn’t send email:

```
v=spf1 -all
```

**This includes:** parked domains, retired marketing domains, [defensive registrations](https://corpuslawinc.com/defensive-domain-name-registrations/) (typosquatting protection), and internal-only subdomains. It takes five minutes per domain and eliminates an entire attack vector.

## Real-World Consequences: The Brazilian Government Case

Think SPF misconfigurations only cause minor inconveniences? According to [documented cases from CIGA](https://conhecimento.ciga.sc.gov.br/books/ciga-camara/page/spf-e-mails-bloqueados-nas-camaras-problema-de-dns/export/pdf), Brazilian municipal government chambers experienced “recurring email blocking issues” that prevented communication with **judicial tribunals**.![Spf Record Example 4440](https://media.mailhop.org/autospf/spf-record-example-4440-1791460787648.jpg) _When Email Goes Missing — Source: CIGA Knowledge Base (2023)_

**Consider the implications:** legal deadlines missed, official correspondence undelivered, government operations disrupted—all because of [DNS configuration](https://phoenixnap.com/kb/dns-configuration) errors. The word “recurring” is particularly damning. This wasn’t a one-time mistake but an ongoing operational failure.

## Advanced Dig Techniques for Power Users

Once you’ve mastered the basics, these advanced techniques will level up your **SPF analysis**:

### Check DNS Propagation Across Servers

`dig TXT example.com @8.8.8.8 +short` — Google DNS`dig TXT example.com @1.1.1.1 +short` — Cloudflare DNS`dig TXT example.com @ns1.example.com +short` — Authoritative server

Inconsistent results indicate propagation issues—common after DNS changes.

### Trace the Full Resolution Path

```
dig TXT example.com +trace`
```

This shows every step from root **DNS servers** to your record. Essential for diagnosing [DNSSEC](https://www.ibm.com/think/topics/dnssec) issues or delegation problems.

### Verify DNSSEC Protection

```
dig TXT example.com +dnssec
```

**DNSSEC prevents attackers** from [injecting malicious](https://cybernews.com/security/wordpress-essential-plugins-injected-malicious-code/) DNS responses. Without it, someone could theoretically spoof your SPF record.![Spf Record Checker 3330](https://media.mailhop.org/autospf/spf-record-checker-3330-1791461158830.jpg) _dig Command Options by Use Case — Source: dig man pages_

_Each technique serves a different diagnostic purpose. Choose based on what you’re troubleshooting._

## Building Your SPF Monitoring System

Manual checks are great for troubleshooting. But for ongoing security, you need **automated monitoring**. Here’s a simple bash script:

```
#!/bin/bashEXPECTED_SPF='"v=spf1 include:_spf.google.com -all"
'CURRENT_SPF=$(digTXTexample.com+short|grepspf1)
if["$CURRENT_SPF" != "$EXPECTED_SPF" ]; then
echo "ALERT: SPF record changed!" | mail -s "SPF Alert" security@example.comfi mailto:security@example.com
fi)
```

Run this via cron daily. Unexpected changes could indicate: someone accidentally modified DNS, an attacker compromised your [DNS management](https://opensrs.com/blog/what-are-dns-management-services), or a well-meaning colleague “fixed” something they shouldn’t have touched.

## Your SPF Implementation Checklist

Before you close this tab, here’s your action plan:

• **Audit all domains you control**—not just primary mail domains. Include parked domains, subdomains, and retired properties.

• **Implement null SPF for non-mail domains**—`v=spf1` `-all` takes seconds and prevents spoofing.

• **Check the complete authentication triad**—SPF, [DKIM](https://autospf.com/blog/exchange-server-dkim-setup-configure-dkim-on-prem-exchange-guide/), and [DMARC](https://autospf.com/blog/what-is-dmarc-email-authentication-guide/). One isn’t enough.

• **Count your DNS lookups**—stay under 10 or your SPF silently fails.

• **Test in monitoring mode first**—use `~all` before enforcing with `-all`.

• **Set up automated monitoring**—detect changes before they cause outages.

• **Document your expected configuration**—you can’t catch drift if you don’t know the baseline.

Email security isn’t glamorous, but it’s foundational. Every [phishing attack](https://www.infosecurity-magazine.com/news/fake-bank-of-america-phishing-scam/) starts with a [spoofed email](https://www.bleepingcomputer.com/news/google/google-now-blocks-spoofed-emails-for-better-phishing-protection/). Every [BEC (business email compromise) scam](https://foleyhoag.com/news-and-insights/blogs/security-privacy-and-the-law/2026/april/business-email-compromises-current-legal-trends-and-key-strategies/) exploits weak authentication. The dig command is your first line of defense—use it wisely.

## References

1. Revisiting Email Forwarding Security under the Lens of Email Authentication Protocols (2022). <https://par.nsf.gov/servlets/purl/10327874>
2. Active Cyber Defence (ACD): The Fourth Year - National Cyber Security Centre UK (2021). <https://www.ncsc.gov.uk/files/Active-Cyber-Defence-ACD-The-Fourth-Year.pdf>
3. What is DNS? How Domain Name System works - USPTO Public Information Document (2023). [https://ptacts.uspto.gov/ptacts/public-informations/petitions/1556023/download-documents?artifactId=hNYJFPaEzScr5f170uAD4ly1MZtTmqWOz4NlUx5HVLwJIH-oOqg5\_K0](https://ptacts.uspto.gov/ptacts/public-informations/petitions/1556023/download-documents?artifactId=hNYJFPaEzScr5f170uAD4ly1MZtTmqWOz4NlUx5HVLwJIH-oOqg5K0)
4. SPF – E-mails bloqueados nas Câmaras (problema de DNS) - CIGA Knowledge Base (2023). <https://conhecimento.ciga.sc.gov.br/books/ciga-camara/page/spf-e-mails-bloqueados-nas-camaras-problema-de-dns/export/pdf>

![Brad Slavin](https://media.mailhop.org/autospf/images/authors/brad-slavin.jpg) 

[ Brad Slavin ](/authors/brad-slavin/) 

General Manager

General Manager of DuoCircle. Product strategy and commercial lead for AutoSPF's 2,000+ customer base.

[LinkedIn Profile →](https://www.linkedin.com/in/bradslavin) 

## Ready to get started?

Try AutoSPF free — no credit card required.

[ Book a Demo ](/book-a-demo/) 

Scan Your Domain Now

Instantly scan your domain for DKIM, SPF, and DMARC issues

Check My Domain 

Share this article

[ ](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Fautospf.com%2Fblog%2Fdig-command-cheat-sheet-query-spf-records-like-security-pro%2F) [ ](https://twitter.com/intent/tweet?text=The%20dig%20Command%20Cheat%20Sheet%3A%20How%20to%20Query%20SPF%20Records%20Like%20a%20Security%20Pro&url=https%3A%2F%2Fautospf.com%2Fblog%2Fdig-command-cheat-sheet-query-spf-records-like-security-pro%2F) [ ](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fautospf.com%2Fblog%2Fdig-command-cheat-sheet-query-spf-records-like-security-pro%2F) Copy 

Related Articles

- [ ![permanent error](https://media.mailhop.org/autospf/images/2024/07/spf-record-office-365-4110.jpg)  Fix '554 5.7.5 Permanent Error Evaluating DMARC Policy' Advanced ](/blog/554-5-7-5-permanent-error-in-dmarc-and-how-to-fix-it/)
- [ ![cybersecurity trends](https://media.mailhop.org/autospf/images/2024/09/spf-checker-52320.jpg)  8 cybersecurity trends that will redefine the digital landscape in 2024 Advanced ](/blog/8-cybersecurity-trends-that-will-redefine-the-digital-landscape-in-2024/)
- [ ![Protect Your Domain](https://media.mailhop.org/autospf/images/2026/03/spf-validator-5901.jpg)  Advanced SPF Record Testing: Protect Your Domain from Permerror Issues Advanced ](/blog/advanced-spf-record-testing-protect-your-domain-from-permerror-issues/)
- [ ![Advanced SPF Validation](https://media.mailhop.org/autospf/images/2026/05/kitterman-spf-5620.jpg)  Advanced SPF Validation Tips To Eliminate Permerror And Lookup Issues Advanced ](/blog/advanced-spf-validation-tips-to-eliminate-permerror-and-lookup-issues/)

## Related Articles

[  Advanced 8m  Fix '554 5.7.5 Permanent Error Evaluating DMARC Policy'  Jul 9, 2024 ](/blog/554-5-7-5-permanent-error-in-dmarc-and-how-to-fix-it/)[  Advanced 6m  8 cybersecurity trends that will redefine the digital landscape in 2024  Sep 20, 2024 ](/blog/8-cybersecurity-trends-that-will-redefine-the-digital-landscape-in-2024/)[  Advanced 13m  Advanced SPF Record Testing: Protect Your Domain from Permerror Issues  Mar 3, 2026 ](/blog/advanced-spf-record-testing-protect-your-domain-from-permerror-issues/)[  Advanced 12m  Advanced SPF Validation Tips To Eliminate Permerror And Lookup Issues  May 4, 2026 ](/blog/advanced-spf-validation-tips-to-eliminate-permerror-and-lookup-issues/)

```json
{"@context":"https://schema.org","@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com","logo":{"@type":"ImageObject","url":"https://autospf.com/images/autospf-logo.png"},"description":"Automatic SPF flattening and email authentication management. Resolve SPF lookup limits, flatten SPF records, and maintain email deliverability across all your domains.","parentOrganization":{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138883901","name":"DuoCircle LLC","url":"https://www.duocircle.com","sameAs":["https://www.wikidata.org/wiki/Q138883901","https://www.crunchbase.com/organization/duocircle-llc","https://www.linkedin.com/company/duocircle","https://github.com/duocircle"],"subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"sameAs":["https://www.wikidata.org/wiki/Q138897474","https://www.linkedin.com/company/autospf","https://x.com/autospf01","https://www.g2.com/products/autospf/reviews"],"contactPoint":{"@type":"ContactPoint","contactType":"customer support","url":"https://autospf.com/contact-us/"},"knowsAbout":["SPF Record Flattening","Sender Policy Framework","Email Authentication","DNS Management","DMARC","DKIM"]}
```

```json
{"@context":"https://schema.org","@type":"WebSite","name":"AutoSPF","url":"https://autospf.com","description":"Automatic SPF flattening and email authentication management. Resolve SPF lookup limits, flatten SPF records, and maintain email deliverability across all your domains.","publisher":{"@type":"Organization","name":"AutoSPF","url":"https://autospf.com","logo":{"@type":"ImageObject","url":"https://autospf.com/images/autospf-logo.png"},"description":"Automatic SPF flattening and email authentication management. Resolve SPF lookup limits, flatten SPF records, and maintain email deliverability across all your domains.","parentOrganization":{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138883901","name":"DuoCircle LLC","url":"https://www.duocircle.com","sameAs":["https://www.wikidata.org/wiki/Q138883901","https://www.crunchbase.com/organization/duocircle-llc","https://www.linkedin.com/company/duocircle","https://github.com/duocircle"],"subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]}}}
```

```json
{"@context":"https://schema.org","@type":"BlogPosting","headline":"The dig Command Cheat Sheet: How to Query SPF Records Like a Security Pro","description":"Learn how to use the dig command to query SPF records, troubleshoot DNS issues, check the 10-lookup limit, and strengthen email security.","url":"https://autospf.com/blog/dig-command-cheat-sheet-query-spf-records-like-security-pro/","datePublished":"2026-10-08T00:00:00.000Z","dateModified":"2026-10-08T00:00:00.000Z","dateCreated":"2026-10-08T00:00:00.000Z","author":{"@type":"Person","@id":"https://autospf.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://autospf.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin is the General Manager of DuoCircle, the company behind AutoSPF, DMARC Report, Phish Protection, and Mailhop. He founded DuoCircle in 2014 to solve the SPF 10-DNS-lookup problem at scale and has led the company's growth to 2,000+ customers. Brad's focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement) rather than hands-on DNS engineering.","image":"https://media.mailhop.org/autospf/images/authors/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"AutoSPF","url":"https://autospf.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com","logo":{"@type":"ImageObject","url":"https://autospf.com/images/autospf-logo.png"},"description":"Automatic SPF flattening and email authentication management. Resolve SPF lookup limits, flatten SPF records, and maintain email deliverability across all your domains.","parentOrganization":{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138883901","name":"DuoCircle LLC","url":"https://www.duocircle.com","sameAs":["https://www.wikidata.org/wiki/Q138883901","https://www.crunchbase.com/organization/duocircle-llc","https://www.linkedin.com/company/duocircle","https://github.com/duocircle"],"subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"sameAs":["https://www.wikidata.org/wiki/Q138897474","https://www.linkedin.com/company/autospf","https://x.com/autospf01","https://www.g2.com/products/autospf/reviews"],"contactPoint":{"@type":"ContactPoint","contactType":"customer support","url":"https://autospf.com/contact-us/"},"knowsAbout":["SPF Record Flattening","Sender Policy Framework","Email Authentication","DNS Management","DMARC","DKIM"]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://autospf.com/blog/dig-command-cheat-sheet-query-spf-records-like-security-pro/"},"articleSection":"advanced","keywords":"","image":{"@type":"ImageObject","url":"https://media.mailhop.org/autospf/spf-lookup-7770-1791457264204.jpg","caption":"SPF Verification Workflow Guide"},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}}
```

```json
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://autospf.com/"},{"@type":"ListItem","position":2,"name":"Blog","item":"https://autospf.com/blog/"},{"@type":"ListItem","position":3,"name":"Advanced","item":"https://autospf.com/advanced/"},{"@type":"ListItem","position":4,"name":"The dig Command Cheat Sheet: How to Query SPF Records Like a Security Pro","item":"https://autospf.com/blog/dig-command-cheat-sheet-query-spf-records-like-security-pro/"}]}
```
