Generator / Guides / Lookup limit
The SPF 10-lookup limit, explained
Most broken SPF records aren't misspelled. They're simply too big: the services listed in them ask for more than 10 DNS lookups, and receivers stop reading. Here is exactly what counts, and how to fix it.
The rule
The SPF standard says a receiving server must stop after 10 DNS lookups while checking one record. If the record needs more, the result is a permerror (permanent error), and DMARC counts that as an SPF failure: your record stops protecting you.
Source: RFC 7208, section 4.6.4, checked Oct 2026
What costs a lookup
include:,a,mx,ptrandexists:each cost one.- The
redirect=modifier costs one. ip4:,ip6:andallcost nothing: they don't need DNS.- Includes inside includes count too.
include:_spf.google.comis one lookup for itself plus the lookups inside Google's own record. That's why this site resolves every include live instead of just counting them.
The second, quieter limit: void lookups
A "void" lookup is one that finds nothing (no record, or an empty answer). The standard says checkers should stop after 2 of them. An include that points at a name with no SPF record, often a typo or a service you stopped using, uses one up. The generator flags includes that publish nothing.
Source: RFC 7208, section 4.6.4, checked Oct 2026
Five ways to get back under 10
- Remove services you no longer use. The old newsletter tool, the CRM you trialled. Each one is at least one lookup.
- Drop
aandmxunless your website or mail server really sends mail itself. Most small businesses send through Google or Microsoft, which are already covered by their include. - Never use
ptr. The standard says it "SHOULD NOT be published": it's slow and unreliable, and it costs a lookup. - Use
ip4:/ip6:for your own fixed servers. They're free. Only do this for addresses you control; a provider's addresses change. - Send bulk mail from a subdomain (for example news.yourdomain.com) with its own SPF record. Each name gets its own 10 lookups.
Source: RFC 7208, section 5.5 (ptr), checked Oct 2026
Be careful with "SPF flattening" services that replace includes with long lists of IP addresses. They work only while someone keeps the list updated; when a provider changes its addresses, the flattened record silently goes wrong.
