Skip to content

SPF “too many DNS lookups” checker

SPF allows 10 DNS lookups in total, including those inside nested includes. Go over and receivers return PermError, so SPF fails for every message. Enter your domain to see the full lookup tree.

What counts as a lookup

include:, a, mx, ptr, exists: and redirect= each cost one lookup, and every include is followed and counted too. ip4:, ip6: and all cost nothing. When we checked in October 2026, Google Workspace’s include cost 1 lookup, Microsoft 365’s 1, Zoho’s 2 and Mailgun’s 5. Providers change these, so check the real total with the tool above.

How to get back under 10

Delete includes for tools you no longer use. That is the most common fix. Drop a and mx if those servers never send mail. Move marketing or transactional mail to a subdomain (for example mail.example.com) with its own SPF record. Flattening (replacing includes with IP ranges) works, but it breaks silently when the provider changes IPs, so monitor it.

Monitor it instead of checking by hand

Get warned before the next new tool pushes you over 10 again. Plans from $9/month after a 14-day free trial. No card to start.

Questions

Is the limit really 10?

Yes. RFC 7208 section 4.6.4 sets the limit at 10 DNS-querying mechanisms per SPF evaluation. Gmail, Microsoft and most other receivers enforce it.

Does SPF flattening fix it permanently?

No. It hard-codes the provider’s current IP ranges. When they change, legitimate mail fails SPF. If you flatten, re-check regularly. SenderBeacon’s drift alerts are built for exactly that.

More free checks

Check a provider setup