SPF too many DNS lookups: how to fix it
SPF allows 10 DNS lookups. Go over and SPF fails for every email (permerror). How to count them, cut them and keep the record under the limit.
By the Domain Health Hub team · Updated
- Receivers stop after 10 DNS lookups while checking SPF. One more and the result is a permanent error.
- include, a, mx, ptr, exists and redirect each cost a lookup, and so does everything inside an include.
- Remove old services first, swap a and mx for ip4 ranges, and move bulk senders to a subdomain.
What it means
To stop SPF being used to flood DNS servers, RFC 7208, section 4.6.4 limits a check to 10 terms that need a DNS lookup. When a receiver reaches the eleventh, it stops and returns a permanent error. That means SPF fails for every message from the domain, genuine or not, and DMARC can only pass on DKIM.
It creeps up unnoticed: each new tool brings an include, and some includes contain several more. A record that worked last year can break when a provider adds a lookup to its own record, with no change on your side.
What counts
- include:
- One lookup, plus every lookup inside the included record.
- a mx
- One each. mx also looks up each mail server's address.
- ptr exists
- One each. ptr shouldn't be used at all.
- redirect=
- One, plus the lookups in the record it points at.
- ip4: ip6: all
- Free. No lookup is needed.
Getting under 10
- Remove services the domain no longer uses. Old newsletter tools, a previous email host, a trial CRM. This alone fixes most records.
- Replace a and mx with ip4: ranges when they point at servers you control and whose addresses rarely change.
- Drop ptr; see the ptr page.
- Check each include is needed at the root. Services that use their own return-path domain, or a subdomain of yours (such as SendGrid with automated security), don't need one.
- Move bulk senders to a subdomain, such as news.example.com for newsletters, with its own SPF record and its own 10 lookups.
Microsoft 365 and Google Workspace
include:spf.protection.outlook.com and include:_spf.google.com each cost one lookup today, as both list their addresses directly. A domain that has moved from one to the other often still lists both: remove the one it left.
Flattening
Flattening replaces includes with the IP ranges they contain, which cost nothing. Done by hand it's risky: providers change their ranges, and a hand-flattened record goes stale without anyone noticing. Only flatten if something keeps the ranges up to date.
Questions
Some receivers accept my email anyway. Is it really broken?
Yes. The limit is in the standard, and receivers that enforce it return permerror. Others may give up at a different point. Either way, SPF can't be relied on.
You warned at 9 lookups. Why?
Because the next service a client adds will tip it over, and the provider's own include can grow without warning. The warning is a nudge to tidy up while it still works.
Hear about it the day it breaks.
Daily checks on every client domain, alerts when something changes, and a monthly report card your clients will understand.