Blog

4

min read

Admin

SPF Too Many DNS Lookups: How to Fix the 10 Lookup Limit

SPF Too Many DNS Lookups: How to Fix the 10 Lookup Limit

SPF Too Many DNS Lookups: How to Fix the 10 Lookup Limit

Getting an SPF permerror for too many DNS lookups? Here is what counts toward the limit of 10, and five ways to fix it without breaking mail.

The SPF "too many DNS lookups" error means your SPF record triggers more than 10 DNS lookups when a mail server checks it. When that happens the check returns a permanent error (permerror), and receivers treat SPF as failed. The fix is to cut the lookups below 10 by removing unused includes, replacing includes with IP ranges where it is safe, or splitting sending across subdomains.

You can see your own lookup count in seconds with the free Rhycon email deliverability checker. This guide explains what is being counted and how to fix it.

What SPF actually checks

SPF (Sender Policy Framework) is a TXT record on your domain that lists which servers are allowed to send email for it. When your email arrives, the receiving server looks up the record, then checks whether the sending server's IP is on the list.

A basic record for a Google Workspace domain looks like this:

v=spf1 include:_spf.google.com ~all

Each part has a job. v=spf1 marks it as SPF. include: pulls in another sender's list. The ending (~all or -all) says what to do with anything not on the list.

What counts toward the 10 lookup limit

The SPF standard caps a check at 10 DNS lookups so receivers cannot be forced into endless queries. These mechanisms each cost one lookup: include, a, mx, ptr, exists and redirect. These cost nothing: ip4, ip6 and all.

The catch is that includes are nested. When you add include:_spf.google.com, that record contains its own includes, and every one of them counts. A single include can quietly use three or four of your ten.

Most teams hit the limit by stacking tools: Google Workspace or Microsoft 365, a CRM, a marketing platform, a support desk, a billing tool and a cold email platform, all on one domain.

Why this matters for cold email

If SPF returns permerror, Gmail, Yahoo and Outlook see an unauthenticated sender. Google and Yahoo now require bulk senders to pass SPF or DKIM, and DMARC needs at least one of them to pass and align. A broken SPF record puts all the weight on DKIM and makes every other problem more likely to push you to spam.

How to fix it

  1. List every sender. Check your DMARC reports or your SPF record for every service that sends as your domain. Be honest about which ones still do.

  2. Delete includes for tools you no longer use. This alone fixes most cases.

  3. Replace includes with IP ranges only if the vendor publishes stable ones. This is called flattening. It saves lookups, but if the vendor changes its IPs your record goes stale and mail starts failing. Avoid it for big providers like Google and Microsoft.

  4. Move sending to subdomains. Send marketing from mail.yourdomain.com and transactional from notify.yourdomain.com. Each subdomain has its own SPF record and its own 10 lookups.

  5. Keep one record per domain. Two SPF records on the same domain is also a permerror. Merge them into one.

The cold email rule: separate domains, short records

For outbound, do not send from your main domain at all. Use separate sending domains, each with a short SPF record that only lists the mailbox provider. A cold sending domain on Google Workspace should look like v=spf1 include:_spf.google.com ~all and nothing else. That is one include, a handful of lookups, and no way to hit the limit. If you would rather not run this yourself, Rhycon's managed infrastructure uses Rhycon-owned domains and mailboxes for your outreach.

Other SPF mistakes worth checking

  • Using +all. This allows anyone on earth to send as you.

  • Using ?all. This tells receivers SPF is neutral and gives you no protection.

  • Record too long. A single TXT string is limited to 255 characters, so long records must be split into quoted chunks by your DNS host.

  • Too many void lookups. More than two lookups that return nothing can also cause an error.

Check your record now

Paste your domain into the email deliverability checker. It reads your SPF record, counts the lookups, and flags the common mistakes above. It also checks DKIM, DMARC and MX, which you can read about in our guides to DKIM, DMARC and MX records.

SPF lookup limit FAQs

What happens if SPF has more than 10 lookups?

The check returns permerror. Receivers usually treat that as a failure, so SPF stops helping you and may count against you.

Do ip4 and ip6 count toward the limit?

No. Only mechanisms that need a DNS query count: include, a, mx, ptr, exists and redirect.

Is SPF flattening safe?

It is safe for small, stable vendors if you keep it updated, and risky for large providers that change IPs often. Using subdomains is the safer fix.

Can I have two SPF records?

No. A domain must have exactly one SPF record. Merge them.

Ready to book more meetings?

Good AI Tools