The 10-DNS-Lookup Trap (RFC 7208 §4.6.4)
To protect mail servers from Distributed Denial of Service (DDoS) loops, RFC 7208 mandates that evaluating an SPF record must not trigger more than 10 DNS queries.
Providers like Google Workspace consume 1 lookup, but others (like HubSpot, Zendesk, or Salesforce) can consume 2 to 4 lookups internally. If your combined mechanisms exceed 10 lookups, Gmail and Yahoo return a PermError and drop your emails.
The Single Record Invariant (RFC 7208 §3.2)
A domain name MUST NOT have more than one SPF TXT record published in DNS. If two records exist (e.g., one for Google and another for Mailchimp), mail receivers abort validation immediately.
You must merge all sender authorizations into a single string starting with v=spf1 and ending with your all qualifier. Our smart merger handles this automatically.
Verified Provider Include Directives (2026)
Standard SPF include strings verified against provider documentation and live DNS records.
| Provider | SPF Include Mechanism | DNS Lookups | Notes |
|---|---|---|---|
| Google Workspace | include:_spf.google.com | 1 | Standard for Gmail and Google Workspace accounts |
| Microsoft 365 (Office 365) | include:spf.protection.outlook.com | 1 | Includes Outlook, Exchange Online, and Defender |
| HubSpot Email | include:[portal-id].spf01.hubspotemail.net | 1 | Uses dynamic portal ID routing per HubSpot standard |
| SendGrid (Twilio) | include:sendgrid.net | 1 | Transactional sending infrastructure |
| Amazon SES | include:amazonses.com | 1 | AWS Simple Email Service global authentication |
| Mailchimp | include:servers.mcsv.net | 1 | Marketing campaign servers |
How to Publish Your Generated SPF Record
Open DNS Manager
Log into your domain registrar or DNS hosting provider (Cloudflare, GoDaddy, Namecheap, AWS Route 53, etc.).
Create or Replace TXT Record
Set Record Type to TXT, Host/Name to @ (or leave blank depending on your registrar), and paste the generated string.
Verify Live Propagation
Use our DNS Inspector to ensure the new record is live across global Anycast nameservers.
Frequently Asked Questions About SPF
Everything you need to know about Sender Policy Framework syntax, limits, and best practices.
What is the SPF 10-lookup limit in RFC 7208?
RFC 7208 Section 4.6.4 specifies that the evaluation of an SPF record must not exceed 10 DNS lookups (from include, a, mx, ptr, and exists mechanisms). If a receiver requires more than 10 lookups to evaluate your SPF record, it aborts evaluation with a permanent error (PermError), causing genuine business emails to fail authentication and land in spam folders.
Why can I not have two separate SPF TXT records for one domain?
RFC 7208 Section 3.2 explicitly dictates that a domain MUST NOT publish more than one SPF record. If receiving mail servers (such as Gmail, Yahoo, or Outlook) discover more than one SPF TXT record beginning with "v=spf1", they immediately fail validation with a PermError without even evaluating the contents.
What is the difference between ~all (SoftFail) and -all (Fail)?
~all (SoftFail) indicates that unlisted sending servers are not authorized, but the receiver should still accept the message while marking it suspicious. -all (Fail/HardFail) instructs receivers to reject unlisted senders outright. In modern DMARC setups, ~all is standard practice because DMARC policies (p=quarantine or p=reject) dictate final disposition.
Does an "ip4" or "ip6" directive count toward the 10-lookup limit?
No. IP mechanisms ("ip4:192.0.2.0/24" and "ip6:2001:db8::/32") do not require DNS queries; their values are embedded directly in the record text. As a result, they consume 0 lookups against the RFC 7208 10-lookup budget.
Email Authentication Configured. What’s Next for Inbox Protection?
DNS authentication is the prerequisite. Next-level email deliverability requires robust nameservers, clean business mailboxes, and automated RUA report ingestion.
Google Workspace
Standardize @yourcompany.com on Google Infrastructure
Industry standard business email with native SPF and DKIM signing. Maintain clean sender reputation with dedicated enterprise IP ranges and built-in abuse prevention.
DMARC RUA Report Pipeline
Aggregate XML Telemetry & Spoofing Alerts
Publishing p=reject without monitoring aggregate XML reports (rua=) risks dropping legitimate transactional email. Set up automated parser dashboards to audit every sending IP.
Enterprise DNS Infrastructure
Sub-second Anycast DNS with DNSSEC Support
Slow or unauthenticated DNS servers cause email verification timeouts (DNS TempError). Pair your SPF and DMARC with Anycast nameservers that support automated DNSSEC.