SPF too many DNS lookups: what counts toward the limit and how to fix it
What SPF too many DNS lookups (PermError) means, which terms count toward the 10-lookup limit, what common senders cost, and how to fix it.
On this page
A warning such as "Your SPF record required more than 10 DNS Lookups to be performed during the test." (MXToolbox (opens in a new tab)) means the checker counted more than 10 DNS-querying terms in your SPF record and the records it includes. Receivers stop at the first term that matches the sending server, but any evaluation that has to go past the tenth lookup term returns a permerror, for example for mail from a server your record doesn't list (RFC 7208 (opens in a new tab)). Count what each term costs, remove or move the ones you don't need, and check again.
What the error means
Sender Policy Framework (SPF) (opens in a new tab) lets a domain publish, in the Domain Name System (DNS) (opens in a new tab), which hosts may use its name, and receivers test the sending server against that list.
Evaluating a record can trigger further DNS queries. The standard caps the terms that cause them at 10 per evaluation, to avoid unreasonable load on the DNS, and an evaluation that exceeds the cap must return a permerror (RFC 7208 section 4.6.4 (opens in a new tab)). A permerror means the domain's published records could not be correctly interpreted, and resolving it needs a change by whoever manages the domain's DNS (section 2.6.7 (opens in a new tab)).
Check your domain now
See the SPF, DKIM and DMARC records your domain publishes and what to fix first. Free, no account needed.
What counts toward the limit
Six terms cause DNS queries and count toward the 10 (RFC 7208 section 4.6.4 (opens in a new tab)):
- the
include,a,mx,ptrandexistsmechanisms - the
redirectmodifier
The all, ip4 and ip6 mechanisms and the exp modifier don't cause DNS queries during evaluation and don't count.
Nested terms count too. An include triggers a recursive evaluation of the included domain's record (section 5.2 (opens in a new tab)), and the cap applies to the whole evaluation, so lookup terms inside included records add to your total. Google's SPF set-up guide (opens in a new tab) says a record can have up to 10 include: tags; because nested terms count as well, a record with fewer than 10 can still go over.
Adding up every lookup term in a record and in everything it includes gives the most lookups an evaluation can use. A receiver works through a record one term at a time, left to right, and stops at the first that matches the sending server (section 4.6.2 (opens in a new tab)). So mail from a server matched early can use fewer lookups than that total. Mail from a server matched late, or not listed at all, goes further, and once it passes the tenth lookup term the result is a permerror.
Two sub-limits apply as well:
- Each
mxterm counts the MX records it queries toward the 10, and each MX record must not lead to more than 10 address (A or AAAA) lookups. - Lookups that come back empty or with a name-error answer are void lookups. Implementations should limit them to two, may make that limit configurable, and going over produces a permerror.
What common senders cost today
Google's SPF set-up guide (opens in a new tab) lists the include to use for common senders. Only the TXT string that begins with v=spf1 counts as the SPF record (RFC 7208 section 4.5 (opens in a new tab)); other TXT strings at the same name, such as verification tokens, are ignored. Each figure below is the most lookups that include can add: one for the include term itself (section 4.6.4 (opens in a new tab)), plus every lookup term in the record it points to, because an include evaluates that record recursively (section 5.2 (opens in a new tab)).
| Sender (as Google names it) | Include | Lookup terms (from live DNS) |
|---|---|---|
| Google Workspace | _spf.google.com |
1 |
| Microsoft Office 365 | spf.protection.outlook.com |
1 |
| Amazon | amazonses.com |
1 |
| Mailchimp | servers.mcsv.net |
1 |
| Salesforce | _spf.salesforce.com |
2 |
| Zendesk | mail.zendesk.com |
1 |
The records at _spf.google.com, spf.protection.outlook.com, amazonses.com, servers.mcsv.net and mail.zendesk.com list only ip4 or ip6 ranges and all, which add nothing to the include's own lookup. The record at _spf.salesforce.com holds an exists term, which adds one more.
So a record for Google Workspace, Salesforce and Zendesk, v=spf1 include:_spf.google.com include:_spf.salesforce.com include:mail.zendesk.com ~all, can use at most 4 of the 10. Because included records are evaluated with yours, your count also depends on records third parties control (MXToolbox (opens in a new tab)), so these figures can change when a provider edits its record.
How to get the count down
- Remove includes for services you no longer use. DemiSignal's check gives this as the way to keep SPF under 10 lookups. Removing an include removes its own lookup (RFC 7208 section 4.6.4 (opens in a new tab)) and every lookup term in the record it evaluated recursively (section 5.2 (opens in a new tab)).
- Use terms that cost nothing where they are accurate.
ip4andip6terms don't count toward the limit, so a server you know by its address can be listed by address instead of throughaormx. - Move a sender to a subdomain. If a service lets you set its envelope sender (MAIL FROM) to a subdomain of yours, publish its SPF record on that exact subdomain and take its include out of your root domain's record. Each subdomain used for email needs its own SPF record (DMARC fail), and that guide covers keeping the subdomain aligned for DMARC.
- Keep one record. Add services to the record you have rather than publishing a second one (SPF record generator).
Other causes of an SPF PermError
- Two SPF records. If the lookup returns more than one record that begins with
v=spf1, the result is a permerror (RFC 7208 section 4.5 (opens in a new tab)). Two records make SPF fail with an error, so add new services to the existing record instead (SPF record generator). - An include that points to a domain with no SPF record. If the included domain publishes none, the
includereturns a permerror (section 5.2 (opens in a new tab)). - Too many void lookups. Going over the void-lookup limit, two by default, also produces a permerror (section 4.6.4 (opens in a new tab)).
What a PermError means for DMARC
DMARC (opens in a new tab) (Domain-based Message Authentication, Reporting, and Conformance) requires an SPF or DKIM pass for a domain aligned with the domain in the From address (RFC 9989 section 1 (opens in a new tab)). For SPF, DMARC relies only on the MAIL FROM check, and only a domain that SPF validated counts (section 4.4.2 (opens in a new tab)). A permerror means the records could not be correctly interpreted (RFC 7208 section 2.6.7 (opens in a new tab)), so SPF gives DMARC no validated domain to align.
The message can still pass DMARC through a valid DomainKeys Identified Mail (DKIM) (opens in a new tab) signature aligned with the From domain. The DMARC fail guide covers SPF and DKIM alignment for services and forwarded mail.
Need hands-on help?
DemiEmail (opens in a new tab) is the hands-on side: DemiSignal provides ongoing email authentication monitoring, and DemiEmail handles scoped technical work. It configures or troubleshoots SPF, DKIM and DMARC across the services sending email for a business, including a review of sending services and DNS. The work, required access, deliverables and price are agreed as the scope, so you know what it costs before the work begins.
Check your record
DemiSignal's check reads the public DNS records of the domain you enter, with no account needed, and flags an SPF record that is close to or over the 10 DNS lookup limit. It counts the total for your domain, including the includes nested in your record (SPF record generator). That total is the most an evaluation can use; how many lookups a given message uses depends on where its sending server matches, since evaluation stops at the first match (RFC 7208 section 4.6.2 (opens in a new tab)). The generator estimates the count from each service's published record as measured in September 2026, while the free check counts it from current DNS.
Sources
- MXToolbox: SPF Included Lookups (opens in a new tab)
- RFC 7208: Sender Policy Framework (SPF) (opens in a new tab)
- RFC 7208 section 1: Introduction (opens in a new tab)
- RFC 7208 section 2.6.7: Permerror (opens in a new tab)
- RFC 7208 section 4.5: Selecting Records (opens in a new tab)
- RFC 7208 section 4.6.2: Mechanisms (opens in a new tab)
- RFC 7208 section 4.6.4: DNS Lookup Limits (opens in a new tab)
- RFC 7208 section 5.2: include (opens in a new tab)
- RFC 9989 (RFC Editor information page) (opens in a new tab)
- RFC 9989 section 1: Introduction (opens in a new tab)
- RFC 9989 section 4.4.2: SPF-Authenticated Identifiers (opens in a new tab)
- RFC 6376: DomainKeys Identified Mail (DKIM) Signatures, section 1 (opens in a new tab)
- Google Workspace: Set up SPF (opens in a new tab)
- Google Workspace: About TXT records (opens in a new tab)
- DemiEmail (opens in a new tab)
- DemiSignal: SPF, DKIM and DMARC check
- DemiSignal: SPF record generator
- DemiSignal: DMARC fail
Tools for this
-
SPF, DKIM and DMARC check
Check the email records a domain publishes today and see what to fix first.
-
SPF record generator
Build an SPF record for the services that send your email.
Frequently asked questions
What does SPF too many DNS lookups mean?
The checker counted more than 10 DNS-querying terms in your SPF record and the records it includes. Any SPF evaluation that has to go past the tenth of those terms returns a permerror, for example for mail from a server the record does not list.
What counts as a DNS lookup in SPF?
The include, a, mx, ptr and exists mechanisms and the redirect modifier, including those inside included records. The all, ip4 and ip6 mechanisms and the exp modifier do not count.
Does an SPF PermError make DMARC fail?
Not on its own. A DMARC pass needs an SPF or DKIM pass for a domain aligned with the From domain. A permerror gives no SPF pass, so the message can still pass DMARC through an aligned DKIM signature.
Check your domain now
See the SPF, DKIM and DMARC records your domain publishes and what to fix first. Free, no account needed.