Skip to content
SPF

Broken SPF include: how to fix it

An SPF include points at a domain with no SPF record, an invalid one or a loop, so SPF fails. How to find the bad include and replace or remove it.

By the Domain Health Hub team · Updated

In short
  • An include that finds no SPF record, or a broken one, makes the whole check a permanent error.
  • The usual cause is a service you've stopped using, or one that changed its include value.
  • Remove the include, or replace it with the value the provider documents today.

What it means

An include: asks the receiver to fetch another domain's SPF record and check the sender against it. If that domain has no SPF record, or its record is invalid, the include can't be evaluated, and RFC 7208, section 5.2 makes the whole result a permanent error. SPF then fails for every message from the domain, not just the ones from that service.

The four kinds

No record
The included domain has no SPF record, or more than one. Often a service you no longer use.
Invalid
The included domain's own record has a syntax error. Theirs to fix, yours to route around.
Lookup failed
We couldn't get an answer. If it repeats, the include is probably wrong.
Loop
Two records include each other, so evaluation would never end.

Fixing it

  1. Note the include the check names.
  2. Ask whether the domain still uses that service. If not, delete the include. That's the answer more often than not.
  3. If it does, open the provider's current set-up page and compare the value. Replace the old include with the new one.
  4. For a loop, find the two records that include each other (usually your own domain and a subdomain) and remove one direction.
  5. Check the domain again to confirm the error has gone.

If an include belongs to an SPF flattening or hosted SPF service you've cancelled, its name stops resolving the day the subscription ends. Replace it with the senders it used to cover before cancelling.

Microsoft 365 and Google Workspace

The current values are include:spf.protection.outlook.com and include:_spf.google.com. A record set up years ago may carry an older value copied from an out-of-date guide; replace it with these.

Questions

The include worked last month. What changed?

Usually the provider. Services rename their SPF records, close old ones when they merge products, or delete them when an account ends. Your record still points at the old name.

Why do you only warn when a lookup fails?

A timeout or server failure can be temporary, and SPF treats it as a temporary error rather than a fail. We warn so you can check it, and only flag it as broken when the include really has no valid record.

Hear about it the day it breaks.

Daily checks on every client domain, alerts when something changes, and a monthly report card your clients will understand.

Start 28-day free trial