Email Fix Pack

Fix SPF permerror: too many DNS lookups

What it means

RFC 7208 section 4.6.4 says SPF implementations must limit DNS-querying terms to 10 during evaluation. Exceeding it returns permerror, a permanent error, and receivers may treat SPF as failed. Mechanisms that count: include, a, mx, ptr, exists, plus the redirect modifier. ip4, ip6 and all do not count. Nested includes count too. RFC 7208 also recommends limiting void lookups (queries returning nothing or NXDOMAIN) to two; exceeding that is also a permerror.

Cause

Stacking many SaaS includes, each of which nests its own includes.

v=spf1 include:_spf.google.com include:mailgun.org include:servers.mcsv.net include:spf.protection.outlook.com include:_spf.salesforce.com mx a ~all

How to fix it

  1. Count lookups by following every include recursively.
  2. Remove includes for services you no longer use, and stale a/mx terms.
  3. Replace a/mx with ip4:/ip6: ranges where they are stable:
    v=spf1 ip4:203.0.113.0/24 include:_spf.google.com ~all
  4. Move bulk senders to a subdomain (for example news.example.com) with its own SPF record.
  5. Use DKIM-aligned DMARC so mail passes even if SPF is imperfect.
  6. Avoid ptr; remove includes pointing to domains that no longer resolve (void lookups).

Check your domain

Not sure what your domain publishes today? The checker reads your live DNS and shows what is missing. If you would rather skip the trial and error, the $29 Email Fix Pack is the fastest route: ready-to-paste records for your domain.

Check your domain free

Sources

  • RFC 7208 section 4.6.4: Limits on DNS Terms

More email delivery fixes

Email Fix Pack

Terms · Privacy · Refunds