All articles
SPFDNS

SPF "Too Many DNS Lookups": How to Fix the 10-Lookup Limit

Exceeding the SPF limit of 10 DNS lookups makes SPF fail for every message. Learn what counts toward the limit and how to get back under it.

July 16, 20266 min read

The SPF specification (RFC 7208) limits how many DNS lookups a receiver may perform while evaluating your record: no more than 10. If your record needs more, the result is a permerror — and receivers treat that as an SPF failure for every message, regardless of which server sent it.

What counts toward the limit

  • include: — 1 lookup, plus every lookup inside the included record (nested includes add up)
  • a and mx — 1 lookup each (and mx can trigger more for the MX hosts)
  • exists:, ptr and the redirect= modifier — 1 lookup each
  • ip4:, ip6: and all — no lookups

How records grow past 10

Each SaaS provider asks you to add its include, and each include often contains further includes. A record like this looks harmless but can easily exceed the limit:

v=spf1 include:_spf.google.com include:spf.protection.outlook.com include:sendgrid.net include:mailgun.org include:servers.mcsv.net include:_spf.salesforce.com mx a ~all

How to fix it

  • Remove unused services. Includes for tools you stopped using years ago are the most common cause
  • Drop mx, a and ptr if those hosts do not actually send mail (ptr is deprecated anyway)
  • Replace includes with ip4:/ip6: ranges for your own servers with static IPs
  • Move senders to subdomains. For example, send newsletters from news.example.com with its own SPF record — each subdomain gets its own 10-lookup budget
  • Rely on DKIM alignment for services that sign with your domain and use their own return-path — they may not need to be in your SPF at all

A word of caution about SPF flattening

Flattening replaces includes with the IP addresses they resolve to. It fixes the lookup count, but providers change their IP ranges without notice, and a stale flattened record silently breaks delivery. Only flatten with a service that re-resolves and updates the record automatically.

Other SPF mistakes to check while you are there

  • More than one SPF record on the same domain — only one v=spf1 TXT record is allowed
  • More than two "void" lookups (lookups that return no records) — also a permerror
  • Using +all, which authorizes the entire internet to send as your domain

Our checker counts the lookups in your SPF record, including nested includes, and warns you before you hit the limit.

Check your domain in seconds

Verify SPF, DKIM, DMARC and blacklist status and get a prioritized list of fixes.