SPF "Too Many DNS Lookups": How to Fix the 10-Lookup Limit
Exceeding the SPF limit of 10 DNS lookups makes SPF fail for every message. Learn what counts toward the limit and how to get back under it.
The SPF specification (RFC 7208) limits how many DNS lookups a receiver may perform while evaluating your record: no more than 10. If your record needs more, the result is a permerror — and receivers treat that as an SPF failure for every message, regardless of which server sent it.
What counts toward the limit
include:— 1 lookup, plus every lookup inside the included record (nested includes add up)aandmx— 1 lookup each (andmxcan trigger more for the MX hosts)exists:,ptrand theredirect=modifier — 1 lookup eachip4:,ip6:andall— no lookups
How records grow past 10
Each SaaS provider asks you to add its include, and each include often contains further includes. A record like this looks harmless but can easily exceed the limit:
v=spf1 include:_spf.google.com include:spf.protection.outlook.com include:sendgrid.net include:mailgun.org include:servers.mcsv.net include:_spf.salesforce.com mx a ~allHow to fix it
- Remove unused services. Includes for tools you stopped using years ago are the most common cause
- Drop
mx,aandptrif those hosts do not actually send mail (ptris deprecated anyway) - Replace includes with
ip4:/ip6:ranges for your own servers with static IPs - Move senders to subdomains. For example, send newsletters from
news.example.comwith its own SPF record — each subdomain gets its own 10-lookup budget - Rely on DKIM alignment for services that sign with your domain and use their own return-path — they may not need to be in your SPF at all
A word of caution about SPF flattening
Flattening replaces includes with the IP addresses they resolve to. It fixes the lookup count, but providers change their IP ranges without notice, and a stale flattened record silently breaks delivery. Only flatten with a service that re-resolves and updates the record automatically.
Other SPF mistakes to check while you are there
- More than one SPF record on the same domain — only one
v=spf1TXT record is allowed - More than two "void" lookups (lookups that return no records) — also a
permerror - Using
+all, which authorizes the entire internet to send as your domain
Our checker counts the lookups in your SPF record, including nested includes, and warns you before you hit the limit.
Check your domain in seconds
Verify SPF, DKIM, DMARC and blacklist status and get a prioritized list of fixes.