Definition · DNS & Email Spoofing
What is SPF Lookup Limit?
RFC 7208 requires that evaluating an SPF record must not trigger more than 10 DNS-querying mechanisms. The cap exists to stop SPF being used to amplify DNS traffic, but in practice it is the single most common reason SPF stops working for organisations that use many third-party sending services.
What counts towards the limit
The mechanisms that require a DNS lookup all count: include, a, mx, ptr, exists, and the redirect modifier. Crucially the count is cumulative and recursive — every include also carries the lookups inside the record it points to, which is why adding one vendor with a nested record can consume several of your ten.
The mechanisms that do not count are ip4, ip6, and all, because they are evaluated from the record itself.
There is also a separate cap on void lookups — queries returning no records — which is lower, and a limit on the number of names an mx mechanism may expand to.
Why exceeding it is worse than it sounds
Going over the limit does not merely drop the extra senders. The evaluation result is permerror, a permanent error, which is not a pass for anyone. Under DMARC, SPF then contributes nothing to authentication, so mail that relied on SPF alignment can fail outright even though the sending servers are perfectly legitimate.
Staying under the cap
- Count your lookups rather than assuming; the total changes whenever a vendor edits their own record
- Remove
includeentries for services you no longer use — this is usually the largest single win - Replace
ptr, which is deprecated for SPF, with explicit address mechanisms - Use
ip4andip6mechanisms for senders with stable addresses, as they cost nothing - Delegate vendors to dedicated subdomains, each with its own SPF record and its own budget of ten
- Consider SPF flattening only with caution: it trades lookups for stale data when a provider changes addresses
Related concepts
Lookup pressure is one reason DKIM and DMARC alignment matter — DKIM survives forwarding and has no equivalent cap. SurfaceLoop validates SPF syntax and counts DNS lookups as part of its DNS and email security checks.