SPF record checker: count your DNS lookups
Mail servers allow an SPF record at most 10 DNS lookups, counted through every nested include:. One over and SPF fails for every message. This counts them the way receivers do and shows which include costs the most.
What the 10-lookup limit is
RFC 7208 limits SPF evaluation to 10 terms that need a DNS query: include:, a, mx, ptr, exists: and redirect=. Lookups inside each include count too, so include:spf.example-provider.com can cost 3 or 4 on its own. ip4:, ip6: and all are free.
Over the limit, receivers return permerror. DMARC treats that as an SPF failure, so mail that relied on SPF to pass DMARC starts landing in spam or getting rejected.
Why it breaks without you changing anything
Your record can stay the same while its cost grows: when a provider adds an include inside its own SPF record, every customer that includes it pays for it. That's why a record that worked last month can fail today.
How to get back under 10
- Remove includes for services you no longer send mail from. This is the most common cause.
- Replace
aandmxwith theip4:/ip6:ranges they resolve to, if those rarely change. - Send bulk or marketing mail from a subdomain (for example
mail.example.com) with its own SPF record. - Flatten an include into IP ranges only as a last resort: the provider can change its ranges and your copy goes stale.
Void lookups
An include that points at a name with no SPF record (or no DNS at all) is a void lookup. Receivers allow two; the third is a permerror too. This checker counts them.