Skip to content

SPF explained, and the 10-lookup limit

How SPF works, why records quietly break as clients add new services, and how to fix a record with too many DNS lookups.

By the Domain Health Hub team · Updated

In short
  • SPF is a TXT record listing the servers allowed to send email for a domain.
  • Receivers may only do 10 DNS lookups while checking it. Go over and SPF fails for every message.
  • Remove old services first; flattening includes into IP ranges is the fallback, and must be kept up to date.

What SPF does

SPF (Sender Policy Framework) lets a domain publish the list of servers allowed to send its email. A receiving server looks up the list and checks the sending server is on it. On its own that only protects the envelope sender, an address people rarely see, which is why SPF matters most as one half of DMARC.

Reading an SPF record

example.com TXT
v=spf1 include:spf.protection.outlook.com include:servers.mcsv.net ip4:203.0.113.10 -all
v=spf1
Marks the record as SPF. There must be exactly one per domain.
include:
Adds another domain's SPF list, usually a service such as Microsoft 365 or Mailchimp.
ip4: ip6:
Allows an address or range directly.
a mx
Allows the domain's own web or mail server addresses.
-all
Everything not listed fails. ~all marks it as suspicious instead.

The 10-lookup limit

To stop SPF being used to flood DNS servers, the standard (RFC 7208) limits a check to 10 DNS lookups. Every include, a, mx, ptr, exists and redirect counts, including the ones inside each included record. Go over and the result is a permanent error: SPF fails for every message, genuine or not.

It creeps up unnoticed. Each service's include can use several lookups of its own, so add a newsletter tool, a helpdesk, an invoicing system and a CRM, and a record that worked last year quietly breaks.

Fixing a record that's over the limit

  1. Remove services the client no longer uses. Old includes are the most common cause.
  2. Drop ptr, which is deprecated, and replace a or mx with the ip4 addresses they point at, if those rarely change.
  3. Move bulk mail to a subdomain, such as news.example.co.uk, with its own SPF record. Many newsletter tools support this, and it keeps marketing mail from affecting the main domain's reputation.
  4. Rely on DKIM where a service signs with the domain's own key: DMARC passes on DKIM alone, so that service may not need to be in SPF at all.

SPF flattening

Flattening replaces includes with the IP ranges they currently resolve to, so they no longer cost lookups. The catch: providers change their ranges without notice, and a flattened record that isn't refreshed starts failing genuine mail. Only flatten with something that re-checks automatically. Hosted SPF in Domain Health Hub re-resolves every 6 hours and keeps the last good record if a lookup fails.

~all or -all?

Use ~all while you're still confirming every sender is listed, then -all. Never use +all, which allows the whole internet to send as the domain, and avoid ?all, which tells receivers to ignore the result. With DMARC at quarantine or reject, the DMARC policy decides what happens to failing mail either way.

Questions

Can a domain have two SPF records?

No. Two records starting v=spf1 make SPF fail with a permanent error. Merge them into one.

Is SPF enough on its own?

No. SPF checks the hidden envelope sender, not the From address people see, and it breaks when mail is forwarded. Use it with DKIM and DMARC.

Do ip4 and ip6 count towards the limit?

No. Only mechanisms that need a DNS lookup count: include, a, mx, ptr, exists and the redirect modifier.

Watch every client's domains, every day.

Reports read for you, and a monthly report card your clients will understand.

Start 28-day free trial