SPF permerror

Your SPF record exceeds 10 DNS lookups, so receivers treat it as broken. Here is the fix.

RFC 7208 caps SPF evaluation at 10 DNS lookups. Go over the limit and receivers return permerror - a permanent error. Mail servers then behave as if you had no valid SPF at all, and under DMARC a permerror counts as SPF fail. This is the single most common way a domain quietly loses SPF protection: every new email tool adds an include, and one day the record tips over the limit.

What an over-limit record looks like

$ dig +short TXT example.com
"v=spf1 include:_spf.google.com include:sendgrid.net
 include:servers.mcsv.net include:_spf.salesforce.com
 include:helpdesk-vendor.com include:spf.protection.outlook.com
 a mx -all"

Each include, a, mx, ptr, exists and redirect costs at least one lookup - and includes recurse, so a single include can cost three or four. ip4 and ip6 entries cost nothing. This record is far past 10 before it finishes evaluating.

First: check how many lookups your domain actually uses

Run a free scan of your DMARC, SPF and DKIM records. It expands nested includes and shows exactly where your SPF stands against the 10-lookup limit.

Free. No signup. Checks DMARC, SPF, DKIM and MX in seconds.

How to fix it, step by step

  1. 1

    Count your actual lookups

    Run your domain through an SPF checker that expands nested includes and shows the total. The visible record understates the real count because each include pulls in its vendor's own includes. You need the fully-expanded number.

  2. 2

    Remove what no longer sends

    Most over-limit records contain includes for tools the company stopped using years ago. Verify each include against the services that actually send mail for the domain today and delete the rest. This alone often gets you under the limit.

  3. 3

    Drop mechanisms that resolve to nothing useful

    The a and mx mechanisms each cost a lookup and are usually redundant - if your web server or MX host never sends outbound mail as your domain, remove them. Never use ptr; it is deprecated and expensive.

  4. 4

    Move bulk senders to subdomains

    Marketing and notification platforms can send from their own subdomain (news.example.com, alerts.example.com) with their own SPF record. Each subdomain gets a fresh 10-lookup budget, and a compromise or listing on one stream no longer taints the root domain.

  5. 5

    Flatten only as a last resort

    Replacing includes with raw ip4 ranges gets the count to near zero, but vendor IPs change without notice - a manually flattened record silently rots. If you must flatten, use a service or scheduled job that re-resolves the includes automatically, and monitor the record for drift.

Related guides

Managing this for multiple client domains?

If you are an MSP or agency, SPF records drift over the lookup limit one client email tool at a time, and nobody notices until mail bounces. DMARC Fleet is building continuous monitoring with per-client white-label reports - transparent pricing from $29/mo for 10 domains. Join the waitlist.