The lookup limit, before it hurts
SPF permits at most ten DNS lookups, counted recursively across every
include: chain. Exceed the limit and the record is not "partly valid" — it returns
permerror, and many receivers treat that as "no SPF at all". The part that worked
before stops working too.
That is exactly what this generator makes visible: every draft is actually
resolved — each include: followed, each a and
mx really queried — so you see the number before the record goes into DNS.
Afterwards it runs through the same RFC 7208 audit as
the check page.
Adjusting an existing record
Enter the domain, press "Build record": an existing SPF record is parsed and fills the
fields. Mechanisms the form has no dedicated field for — a:host,
exists:, macros — are recognised and carried over unchanged instead of quietly
disappearing on rebuild.
Mechanism order is not arbitrary
SPF evaluates left to right. ip4: and ip6: cost no DNS lookup at
all, while include:, a and mx cost at least one each. The
generator therefore puts the IP literals first: a large share of queries is answered before the
lookup budget is touched.
Which all qualifier
-all(hardfail) — anything not in the record is not authorised. The goal. Set it once you are confident every sending system is covered.~all(softfail) — not authorised, but please only mark it. The right intermediate step while you are still collecting. Too weak as a permanent state.?all(neutral) — the domain makes no statement. Offers practically no protection.+all— anyone may send in your name. In practice always a misconfiguration.
When the budget runs out
- Remove includes you no longer use. The most common find: the newsletter tool from three years ago is still in there.
- Replace
mx. It costs one lookup and additionally resolves every MX host. If you only send through one provider, you do not need it. - IP literals instead of includes wherever the provider names fixed addresses — those cost zero lookups.
- Separate subdomains for bulk sending:
news.yourdomaingets its own SPF record with its own budget.
Publishing
The record goes in as a TXT entry on the domain itself, not on a sub-name. A
domain may have exactly one SPF record — two produce permerror. You can
verify the result afterwards with the SPF check.