SPF record checker: count your DNS lookups

Mail servers allow an SPF record at most 10 DNS lookups, counted through every nested include:. One over and SPF fails for every message. This counts them the way receivers do and shows which include costs the most.

What the 10-lookup limit is

RFC 7208 limits SPF evaluation to 10 terms that need a DNS query: include:, a, mx, ptr, exists: and redirect=. Lookups inside each include count too, so include:spf.example-provider.com can cost 3 or 4 on its own. ip4:, ip6: and all are free.

Over the limit, receivers return permerror. DMARC treats that as an SPF failure, so mail that relied on SPF to pass DMARC starts landing in spam or getting rejected.

Why it breaks without you changing anything

Your record can stay the same while its cost grows: when a provider adds an include inside its own SPF record, every customer that includes it pays for it. That's why a record that worked last month can fail today.

How to get back under 10

Void lookups

An include that points at a name with no SPF record (or no DNS at all) is a void lookup. Receivers allow two; the third is a permerror too. This checker counts them.