How the SPF check works
The checker reads the TXT records published at your domain and picks the one that starts with v=spf1. It then follows every include: and redirect= the same way a receiving mail server would, and counts each mechanism that needs a DNS query: include, a, mx, ptr, exists, and redirect. Plain ip4 and ip6 entries are free. Nothing is stored; we only make public DNS queries.
Fixing the most common SPF errors
"Too many DNS lookups" (PermError)
Every marketing, helpdesk, and CRM tool asks you to add its own include, and each one can hide several more lookups inside it. Once the total passes 10, receivers stop evaluating and return PermError. To get back under the limit:
- Remove includes for services you no longer use.
- Drop
aandmxif those servers never send mail, or replace them with theirip4addresses. - Send bulk or marketing mail from a subdomain (for example
news.example.com) with its own SPF record.
More than one SPF record
Adding a second v=spf1 record instead of editing the first is a very common mistake, and it breaks SPF for the whole domain. Merge them into one:
v=spf1 include:_spf.google.com include:sendgrid.net ~all
An include that no longer exists
If a provider retires the hostname you include, the lookup comes back empty and SPF fails with a PermError. Check the provider's current documentation and update or remove the include.
SPF is only one part of email authentication
Gmail and Yahoo now expect bulk senders to pass SPF and DKIM, and to publish a DMARC policy. SPF on its own does not protect the From address your readers see. After SPF is clean, run the DMARC Checker on the same domain.