SPF “too many DNS lookups” checker
SPF allows 10 DNS lookups in total, including those inside nested includes. Go over and receivers return PermError, so SPF fails for every message. Enter your domain to see the full lookup tree.
What counts as a lookup
include:, a, mx, ptr, exists: and redirect= each cost one lookup, and every include is followed and counted too. ip4:, ip6: and all cost nothing. When we checked in October 2026, Google Workspace’s include cost 1 lookup, Microsoft 365’s 1, Zoho’s 2 and Mailgun’s 5. Providers change these, so check the real total with the tool above.
How to get back under 10
Delete includes for tools you no longer use. That is the most common fix. Drop a and mx if those servers never send mail. Move marketing or transactional mail to a subdomain (for example mail.example.com) with its own SPF record. Flattening (replacing includes with IP ranges) works, but it breaks silently when the provider changes IPs, so monitor it.
Monitor it instead of checking by hand
Get warned before the next new tool pushes you over 10 again. Plans from $9/month after a 14-day free trial. No card to start.
Questions
Is the limit really 10?
Yes. RFC 7208 section 4.6.4 sets the limit at 10 DNS-querying mechanisms per SPF evaluation. Gmail, Microsoft and most other receivers enforce it.
Does SPF flattening fix it permanently?
No. It hard-codes the provider’s current IP ranges. When they change, legitimate mail fails SPF. If you flatten, re-check regularly. SenderBeacon’s drift alerts are built for exactly that.
More free checks
- Email domain health check
- SPF record checker
- DMARC record checker
- DKIM record checker
- MX record lookup
- SSL certificate expiry checker
- SPF record generator
- DMARC record generator