On this page
  1. What the error means
  2. What counts toward the limit
  3. What common senders cost today
  4. How to get the count down
  5. Other causes of an SPF PermError
  6. What a PermError means for DMARC
  7. Need hands-on help?
  8. Check your record
  9. Sources

A warning such as "Your SPF record required more than 10 DNS Lookups to be performed during the test." (MXToolbox (opens in a new tab)) means the checker counted more than 10 DNS-querying terms in your SPF record and the records it includes. Receivers stop at the first term that matches the sending server, but any evaluation that has to go past the tenth lookup term returns a permerror, for example for mail from a server your record doesn't list (RFC 7208 (opens in a new tab)). Count what each term costs, remove or move the ones you don't need, and check again.

What the error means

Sender Policy Framework (SPF) (opens in a new tab) lets a domain publish, in the Domain Name System (DNS) (opens in a new tab), which hosts may use its name, and receivers test the sending server against that list.

Evaluating a record can trigger further DNS queries. The standard caps the terms that cause them at 10 per evaluation, to avoid unreasonable load on the DNS, and an evaluation that exceeds the cap must return a permerror (RFC 7208 section 4.6.4 (opens in a new tab)). A permerror means the domain's published records could not be correctly interpreted, and resolving it needs a change by whoever manages the domain's DNS (section 2.6.7 (opens in a new tab)).

Check your domain now

See the SPF, DKIM and DMARC records your domain publishes and what to fix first. Free, no account needed.

What counts toward the limit

Six terms cause DNS queries and count toward the 10 (RFC 7208 section 4.6.4 (opens in a new tab)):

  • the include, a, mx, ptr and exists mechanisms
  • the redirect modifier

The all, ip4 and ip6 mechanisms and the exp modifier don't cause DNS queries during evaluation and don't count.

Nested terms count too. An include triggers a recursive evaluation of the included domain's record (section 5.2 (opens in a new tab)), and the cap applies to the whole evaluation, so lookup terms inside included records add to your total. Google's SPF set-up guide (opens in a new tab) says a record can have up to 10 include: tags; because nested terms count as well, a record with fewer than 10 can still go over.

Adding up every lookup term in a record and in everything it includes gives the most lookups an evaluation can use. A receiver works through a record one term at a time, left to right, and stops at the first that matches the sending server (section 4.6.2 (opens in a new tab)). So mail from a server matched early can use fewer lookups than that total. Mail from a server matched late, or not listed at all, goes further, and once it passes the tenth lookup term the result is a permerror.

Two sub-limits apply as well:

  • Each mx term counts the MX records it queries toward the 10, and each MX record must not lead to more than 10 address (A or AAAA) lookups.
  • Lookups that come back empty or with a name-error answer are void lookups. Implementations should limit them to two, may make that limit configurable, and going over produces a permerror.

What common senders cost today

Google's SPF set-up guide (opens in a new tab) lists the include to use for common senders. Only the TXT string that begins with v=spf1 counts as the SPF record (RFC 7208 section 4.5 (opens in a new tab)); other TXT strings at the same name, such as verification tokens, are ignored. Each figure below is the most lookups that include can add: one for the include term itself (section 4.6.4 (opens in a new tab)), plus every lookup term in the record it points to, because an include evaluates that record recursively (section 5.2 (opens in a new tab)).

Sender (as Google names it) Include Lookup terms (from live DNS)
Google Workspace _spf.google.com 1
Microsoft Office 365 spf.protection.outlook.com 1
Amazon amazonses.com 1
Mailchimp servers.mcsv.net 1
Salesforce _spf.salesforce.com 2
Zendesk mail.zendesk.com 1

The records at _spf.google.com, spf.protection.outlook.com, amazonses.com, servers.mcsv.net and mail.zendesk.com list only ip4 or ip6 ranges and all, which add nothing to the include's own lookup. The record at _spf.salesforce.com holds an exists term, which adds one more.

So a record for Google Workspace, Salesforce and Zendesk, v=spf1 include:_spf.google.com include:_spf.salesforce.com include:mail.zendesk.com ~all, can use at most 4 of the 10. Because included records are evaluated with yours, your count also depends on records third parties control (MXToolbox (opens in a new tab)), so these figures can change when a provider edits its record.

How to get the count down

  • Remove includes for services you no longer use. DemiSignal's check gives this as the way to keep SPF under 10 lookups. Removing an include removes its own lookup (RFC 7208 section 4.6.4 (opens in a new tab)) and every lookup term in the record it evaluated recursively (section 5.2 (opens in a new tab)).
  • Use terms that cost nothing where they are accurate. ip4 and ip6 terms don't count toward the limit, so a server you know by its address can be listed by address instead of through a or mx.
  • Move a sender to a subdomain. If a service lets you set its envelope sender (MAIL FROM) to a subdomain of yours, publish its SPF record on that exact subdomain and take its include out of your root domain's record. Each subdomain used for email needs its own SPF record (DMARC fail), and that guide covers keeping the subdomain aligned for DMARC.
  • Keep one record. Add services to the record you have rather than publishing a second one (SPF record generator).

Other causes of an SPF PermError

What a PermError means for DMARC

DMARC (opens in a new tab) (Domain-based Message Authentication, Reporting, and Conformance) requires an SPF or DKIM pass for a domain aligned with the domain in the From address (RFC 9989 section 1 (opens in a new tab)). For SPF, DMARC relies only on the MAIL FROM check, and only a domain that SPF validated counts (section 4.4.2 (opens in a new tab)). A permerror means the records could not be correctly interpreted (RFC 7208 section 2.6.7 (opens in a new tab)), so SPF gives DMARC no validated domain to align.

The message can still pass DMARC through a valid DomainKeys Identified Mail (DKIM) (opens in a new tab) signature aligned with the From domain. The DMARC fail guide covers SPF and DKIM alignment for services and forwarded mail.

Need hands-on help?

DemiEmail (opens in a new tab) is the hands-on side: DemiSignal provides ongoing email authentication monitoring, and DemiEmail handles scoped technical work. It configures or troubleshoots SPF, DKIM and DMARC across the services sending email for a business, including a review of sending services and DNS. The work, required access, deliverables and price are agreed as the scope, so you know what it costs before the work begins.

Check your record

DemiSignal's check reads the public DNS records of the domain you enter, with no account needed, and flags an SPF record that is close to or over the 10 DNS lookup limit. It counts the total for your domain, including the includes nested in your record (SPF record generator). That total is the most an evaluation can use; how many lookups a given message uses depends on where its sending server matches, since evaluation stops at the first match (RFC 7208 section 4.6.2 (opens in a new tab)). The generator estimates the count from each service's published record as measured in September 2026, while the free check counts it from current DNS.

Sources

Tools for this

Frequently asked questions

What does SPF too many DNS lookups mean?

The checker counted more than 10 DNS-querying terms in your SPF record and the records it includes. Any SPF evaluation that has to go past the tenth of those terms returns a permerror, for example for mail from a server the record does not list.

What counts as a DNS lookup in SPF?

The include, a, mx, ptr and exists mechanisms and the redirect modifier, including those inside included records. The all, ip4 and ip6 mechanisms and the exp modifier do not count.

Does an SPF PermError make DMARC fail?

Not on its own. A DMARC pass needs an SPF or DKIM pass for a domain aligned with the From domain. A permerror gives no SPF pass, so the message can still pass DMARC through an aligned DKIM signature.

Check your domain now

See the SPF, DKIM and DMARC records your domain publishes and what to fix first. Free, no account needed.