Skip to content

Scan your domain with 35 DNS and email security checks at zerohook.org.

What is

SPF lookup limit

RFC 7208 limits SPF evaluation to ten DNS-querying mechanisms and modifiers per check. Mechanisms that count are include, a, mx, ptr, exists, and redirect. Exceeding the limit returns permerror.

Operators sometimes replace long include chains with explicit ip4 and ip6 mechanisms so evaluation stays under the limit. RFC 7208 does not define the word flattening; it defines the limit that motivates that operational change.

Void lookups

RFC 7208 also limits void lookups — DNS answers that are empty or NXDOMAIN during SPF evaluation — to two by default. That is a separate counter from the ten-term limit.

A permerror from either limit needs a DNS change. A temperror from a transient DNS failure may clear on retry without editing the record.

Related errors

The error-code page for too many lookups quotes the same limit. permerror from duplicate v=spf1 records is a different failure mode with the same need for DNS edits.

Temperror from transient DNS failures may clear on retry without changing the TXT record. permerror does not.

RFC 7208 does not define flattening as a term. It defines the counters that cause permerror when nested includes exceed ten DNS-querying mechanisms during one check.