athenschamber.com
Everything on this page was computed while you loaded it — at 2026-09-05 08:01:19 UTC — by reading public DNS through two independent resolvers, Cloudflare and Google, and requiring their answers to agree. No answer above was taken from a previous reading and no mailbox was touched. Reload it and the work is done again. We do keep one line saying this page was loaded and which domain was asked about — a count, so we can tell whether anyone reads what we send. It holds no address, no identifier, no cookie and nothing that could single you out.
Inside the limit
2 of the 10 permitted terms are used.
The count
2 of 10
2 are terms written in your own record. 0 are performed inside records published and edited by other companies, reached through your includes. That second number is the one you cannot fix by editing your own DNS.
The derivation, one line per term, in the order a receiver performs them
| # | Level | Published at | Term | Whose record |
|---|---|---|---|---|
| 1 | 0 | athenschamber.com | include:spf.protection.outlook.com | yours |
| 2 | 0 | athenschamber.com | include:clientemailspf.growthzoneapp.com | yours |
Terms counted are the ones the specification counts: include, a, mx, ptr, exists and the redirect modifier. all, ip4, ip6 and exp cause no DNS query at evaluation time and are not counted.
What this number is, exactly. It is the whole tree, which is the worst case. A receiver evaluates left to right and stops at the first term that matches, so a record above ten does not fail for every sender — it fails for every sender whose evaluation has to walk past the tenth term. A record at or under ten cannot fail this way at all.
Both resolvers, verbatim, name by name
The left column is what Cloudflare’s resolver returned; the right is Google’s. Only SPF records are shown — the other TXT records a domain publishes are none of our business and are filtered out before the two answers are compared.
| Level | Name | Cloudflare | Agree | |
|---|---|---|---|---|
| 0 | athenschamber.com | v=spf1 include:spf.protection.outlook.com include:clientemailspf.growthzoneapp.com -all | v=spf1 include:spf.protection.outlook.com include:clientemailspf.growthzoneapp.com -all | yes |
| 1 | spf.protection.outlook.com | v=spf1 ip4:40.92.0.0/15 ip4:40.107.0.0/16 ip4:52.100.0.0/15 ip4:52.102.0.0/16 ip4:52.103.0.0/17 ip4:104.47.0.0/17 ip6:2a01:111:f400::/48 ip6:2a01:111:f403::/49 ip6:2a01:111:f403:8000::/51 ip6:2a01:111:f403:c000::/51 ip6:2a01:111:f403:f000::/52 -all | v=spf1 ip4:40.92.0.0/15 ip4:40.107.0.0/16 ip4:52.100.0.0/15 ip4:52.102.0.0/16 ip4:52.103.0.0/17 ip4:104.47.0.0/17 ip6:2a01:111:f400::/48 ip6:2a01:111:f403::/49 ip6:2a01:111:f403:8000::/51 ip6:2a01:111:f403:c000::/51 ip6:2a01:111:f403:f000::/52 -all | yes |
| 1 | clientemailspf.growthzoneapp.com | v=spf1 ip4:149.72.161.78 ip4:198.21.0.140 ip4:168.245.100.209 ip4:149.72.32.80 ip4:149.72.32.71 ~all | v=spf1 ip4:149.72.161.78 ip4:198.21.0.140 ip4:168.245.100.209 ip4:149.72.32.80 ip4:149.72.32.71 ~all | yes |
| — | _dmarc.athenschamber.com | v=DMARC1; p=none; pct=100; rua=mailto:re+klkl93bel6u@dmarc.postmarkapp.com; sp=none; aspf=r; | v=DMARC1; p=none; pct=100; rua=mailto:re+klkl93bel6u@dmarc.postmarkapp.com; sp=none; aspf=r; | yes |
DNS queries made to produce this page: 8.
What your DMARC record asks receivers to do
v=DMARC1; p=none; pct=100; rua=mailto:re+klkl93bel6u@dmarc.postmarkapp.com; sp=none; aspf=r;
| Tag | Value | What it means |
|---|---|---|
v | DMARC1 | protocol version; a DMARC record must begin with v=DMARC1 |
p | none | requested policy for this domain: none, quarantine or reject |
pct | 100 | the percentage of failing messages the requested policy is applied to |
rua | mailto:re+klkl93bel6u@dmarc.postmarkapp.com | where aggregate reports are sent |
sp | none | requested policy for subdomains of this domain |
aspf | r | SPF identifier alignment: r relaxed, s strict |
Your p tag asks receivers to take no action on the basis of DMARC beyond sending reports.
Your sp tag asks the same receivers to take no action on the basis of DMARC beyond sending reports for mail from every subdomain. RFC 7489 section 6.3 makes sp override p for subdomains, so where the two differ, the subdomain line is the weaker one.
The clauses this page counted under, word for word
RFC 7208 section 4.6.4: “SPF implementations MUST limit the total number of those terms to 10 during SPF evaluation, to avoid unreasonable load on the DNS. If this limit is exceeded, the implementation MUST return ‘permerror’.”
RFC 7208 section 4.5: “If the resultant record set includes more than one record, check_host() produces the ‘permerror’ result.”
RFC 7208 section 7: macros are expanded per message from the client IP address, the sender and the HELO identity — which is why a term containing %{ is counted here and not followed.
What this page did not measure
It did not read your mail and could not. It says nothing about whether your mail is being delivered, whether anyone has forged your domain, or whether the addresses inside your record are the right ones. It reads what your domain publishes, counts the terms the published specification counts, and quotes the clause it counted them under.
What we sell, plainly
Two things, both fixed price, both delivered by email, both produced by the same reader that wrote this page.
$29 — a full written audit of one domain: every check, the standards clause each one evaluates, the exact strings read, and the change we would make. Order the $29 audit
$99 — the same read across up to 25 domains, one row each, for a firm that carries other organisations’ domains as well as its own. Order the $99 roster read
Either is emailed within one business day or refunded in full without you asking. You owe us nothing for this page: the reading, the records and the clauses are yours to keep and to check whether or not you ever buy anything.
Read another domain · The free lookup counter · The free record check · What else we do