What is / Full version
SPF evaluation limits
Ten DNS-querying terms and two void lookups are hard limits in RFC 7208.
Short answerAll topics in What is
Why includes accumulate
Each include may pull in another SPF record with its own mechanisms. Marketing tools, ticketing systems, and corporate relays often add includes until the chain exceeds ten lookups.
Replacing includes with explicit IP lists reduces lookups but shifts maintenance to the domain owner whenever the provider changes address ranges.
Counters
The ten-term limit counts mechanisms that cause DNS queries during evaluation. The void-lookup limit is separate and also returns permerror when exceeded.
Temperror from a resolver timeout is not fixed by flattening. Only permerror from limits or syntax requires a published record change.
The error-code page on this site for too many lookups quotes the same RFC 7208 limits in the context of Gmail and generic receivers.
Subdomains without their own SPF record inherit evaluation through the parent only when the parent explicitly covers them. A dedicated subdomain SPF is often cleaner than a single apex record stuffed with every vendor include.
Operational responses
When includes nest deeply, evaluation may hit permerror before reaching an all mechanism. Operators sometimes list provider IP ranges directly with ip4 and ip6 to stay under the limit.
Void lookups have their own limit of two by default. Hitting either limit requires changing the published TXT, not retrying the same message indefinitely.
The redirect modifier can replace the entire record with another host's SPF. It still counts toward the ten-term limit when evaluated.