Email Authentication

SPF lookup limit check

An SPF record may trigger at most 10 DNS lookups. Past that, receivers treat it as broken and your mail loses its SPF pass.

Check this on your own domain now. It is free with a DomainGuard account, reads only public records, and gives you a report you can send to whoever runs your website.

What we look at

We follow every include, a, mx, redirect and exists in your SPF record and count the DNS lookups a receiving server has to make, plus any that return nothing (void lookups).

Why it matters to your business

The limit is easy to break without noticing: each new tool you sign up for adds another include, and some includes contain several more. Once the count passes 10, receivers stop evaluating and return an error, so every message you send fails SPF even though the record looks fine.

How to fix it

  1. Remove includes for services you no longer use.
  2. Replace mx or a mechanisms with the ip4/ip6 addresses they point to, if those addresses are stable.
  3. Move bulk senders (newsletters, marketing) to a subdomain such as mail.yourdomain.com with its own SPF record.

If you would rather not touch DNS or server settings yourself, forward this page and your report to whoever manages your website, or ask us to do it.

Keep an eye on it

A one-off check tells you how things stand today. On Starter and up, DomainGuard re-checks the domains it watches every day and alerts you in the app when something important changes, so you hear about it before a customer does.

Tools that include this check