SPF PermError: too many DNS lookups
Find out how many DNS lookups your SPF record really costs, and which include to drop.
What you are seeing
- spf=permerror (too many DNS lookups)
- Your SPF record has exceeded 10 DNS lookups
- Received-SPF: permerror (domain of example.com: too many DNS lookups)
What it means
RFC 7208 caps SPF evaluation at 10 DNS-querying mechanisms. The receiver stops counting at the eleventh, returns a permanent error, and never reaches your `all` qualifier. Nothing in your record is evaluated past that point.
A PermError is not a soft failure. DMARC treats it as an SPF failure, so if DKIM is missing or unaligned the message fails DMARC outright and an enforcing policy applies.
The cost is not the number of includes you typed. Every `include`, `a`, `mx`, `ptr` and `exists` counts, and each nested include inside those records counts too. One `include:` that resolves to a provider with four of its own includes costs five.
Why it happens
- Nested includes from a large provider
- Some senders publish an include that fans out. A record can look like three includes and resolve to twelve lookups once the nesting is followed.
- Senders you stopped using
- An include for a newsletter tool or help desk you switched away from still costs lookups. This is the cheapest thing to remove and usually enough on its own.
- `mx` and `a` left in from a template
- An `mx` mechanism costs one lookup plus one per MX host returned. If your inbound provider publishes five MX hosts, `mx` costs six lookups and authorises servers that never send your mail.
- Void lookups
- A mechanism pointing at a hostname that no longer resolves counts toward a separate limit of two void lookups, which also produces a PermError even when you are under 10.
How to fix it
- 1Count the real cost per mechanism. Run the check above. MailVakt resolves every include, a, mx, exists and redirect and reports the lookup count each mechanism contributes, so you can see which one to cut first.
- 2Remove senders you no longer use. Drop includes for retired services. Confirm from the DMARC aggregate reports or your sending tool list before removing anything that still sends.
- 3Replace `mx` and `a` with what actually sends. Inbound mail servers do not need SPF authorisation. If your mail leaves through a provider, the provider include is enough and `mx` can go.
- 4Move marketing mail to a subdomain. Giving bulk mail its own sending subdomain gives it a separate SPF record with its own budget of 10, and keeps reputation separated. It needs the subdomain to be the envelope sender in the tool, not just the visible From.
- 5Flatten only as a last resort. Replacing an include with its current IP ranges removes lookups but freezes a list your provider will change without telling you. If you flatten, re-check on a schedule.
Questions
- Does the 10 lookup limit count includes or DNS queries?
- DNS-querying mechanisms, resolved recursively. `include`, `a`, `mx`, `ptr` and `exists` each count, and the mechanisms inside an included record count against your total too. `ip4` and `ip6` cost nothing.
- Will my mail stop being delivered?
- Not necessarily. A PermError is treated as an SPF failure, so delivery depends on DKIM, alignment and your DMARC policy. With DKIM passing and aligned, DMARC can still pass. With p=reject and no aligned DKIM, mail is rejected.
- Can I just split SPF into two records?
- No. Two `v=spf1` TXT records on the same name is itself a PermError. One record per domain, always.
- Is SPF flattening safe?
- It works and it is sometimes the only option, but it converts a maintained list into a static one. Your provider can change IP ranges at any time, and a stale flattened record fails SPF for real mail.
Fix this from ChatGPT or Claude
MailVakt is an MCP server, so your assistant can run this check itself, read the findings and walk you through the DNS edit. Ask it:
“My SPF record for example.com fails with too many DNS lookups. Count the lookups per mechanism and give me a record under the limit.”
- Claude: Settings → Connectors → Add custom connector, then paste
https://mcp.mailvakt.com/mcp. - Cursor and other MCP clients: add the same address as an MCP server. Setup details.
Checks are free and need no account. Sign in only to collect DMARC reports for a domain.