SPF records explained: syntax, lookups & the 10-lookup limit
Sender Policy Framework (SPF) is a DNS record that lists which servers are allowed to send email for your domain. When a receiving server gets mail claiming to be from you, it checks your SPF record — if the sending server isn't listed, the message looks forged.
Where the record lives
SPF is a TXT record published at your domain root (the @ or bare-domain host in your DNS panel). A typical record looks like this:
v=spf1 include:_spf.google.com ip4:192.0.2.0/24 -allReading it left to right
- v=spf1 — the version tag. It must come first, exactly once.
- include:_spf.google.com — "also accept whatever Google's SPF record authorizes." Each include: triggers a DNS lookup, and includes can nest.
- ip4:192.0.2.0/24 / ip6: — authorize a specific IP or range. No DNS lookup needed.
- a and mx — authorize the domain's A or MX records. Each costs a lookup.
- -all — the default policy at the end. -all means "fail everything else" (recommended once tested). ~all is a soft fail for the testing phase; ?all is neutral and protects nothing.
Letters before a mechanism are qualifiers: + pass (default), - fail, ~ soft fail, ? neutral. Anything after the all mechanism is never evaluated, so put it last.
The 10 DNS-lookup limit
This is the rule that breaks most SPF records. During evaluation, a receiver will perform at most 10 DNS lookups (mechanisms like include:, a, mx, exists: and the redirect= modifier). Nested includes count too — if you include a provider whose record includes three more providers, all of them count against your 10.
Exceed the limit and receivers return a permerror — effectively "I couldn't evaluate this," which many providers treat like a failure. The fix is usually to replace includes with direct ip4:/ip6: entries (which cost zero lookups) or to remove providers you no longer send through.
Common mistakes
- More than one SPF record. A domain must publish exactly one. Two records = permerror.
- Using ptr. It's slow, unreliable, and discouraged — remove it.
- Forgetting the sending tool. Every platform that sends as you (Google Workspace, Instantly, your CRM) must be authorized, or its mail fails SPF.
- Publishing +all. This authorizes the entire internet. Never use it.
Check your own record
Paste your SPF value into the free SPF audit tool to check syntax, policy strength, and declared lookup count in plain language — or use the builder to assemble a clean record from scratch.
Want it set up correctly, first time?
I configure SPF, DKIM and DMARC for cold emailers and businesses — usually within 48 hours, working with you directly.
WhatsApp Saqib See packages