What the recipient does about it
A temperror is explicitly meant to be retryable. Most receivers answer with a 4xx code, the mail stays queued at the sender and is retried. That is why the symptom often does not register as an error at all but as a delay — mail arrives twenty minutes or two hours late and nobody looks for the cause in DNS.
With DMARC it weighs more heavily: if SPF lands on temperror and no valid DKIM signature is present, DMARC evaluation cannot conclude. Under p=reject the receiver then decides whether to defer or discard.
The five realistic causes
- An authoritative nameserver is not answering. Not necessarily yours — it is enough for a server behind an
include:to fail. Your zone is then spotless and the check still fails. - A broken DNSSEC chain. An expired signature or a key rollover that was not carried through produces SERVFAIL at validating resolvers. To SPF that looks exactly like an outage — and it only hits receivers that validate, which is why it appears sporadic.
- Answer too large for UDP, no TCP fallback. Long TXT chains exceed the UDP limit; if a firewall blocks DNS over TCP on port 53, resolution breaks precisely when the record grows.
- Too many queries in the chain. Every
include:is its own resolution. A record that maxes out ten lookups has ten opportunities to time out — the probability of atemperrorrises with the length of the chain. - Rate limiting at the nameserver. Large receivers query often; a nameserver with a strict rate limit then goes quiet for a while.
Measuring it
The fault is sporadic, so a single query proves little. What helps is asking each authoritative server individually rather than trusting the local cache:
If one server in the set does not answer, or answers differently from the others, you have found the cause. The same check belongs on every domain appearing in an include: — the fault sits there more often than in your own zone.
Telling it apart
permerror is the opposite: the record was read and is invalid, for instance through an exceeded lookup limit. That repeats identically on every attempt and has to be fixed in the record. none means there is no SPF record at all.