Solo ads sellers / Blog / SPF lookup limit

Solo ads blog

An SPF record can fail by trying to be helpful

Answer An SPF record can fail because it is too helpful. RFC 7208, from April 2014, stops evaluation after ten DNS lookups. A permanent error is the result, not a soft warning. A solo ad domain that keeps adding tools can authenticate nothing, while the copy stays exactly the same.

Cream stationery and a teal accent on a dark navy desk
The record is a short list. Past the limit, the list stops meaning yes.

The note that started this: RFC 7208: Sender Policy Framework (SPF), IETF, April 2014.

SPF is the list of who may send for a domain. Sellers talk about it as a switch that is either on or off. It is a list with a budget. Every time someone adds a platform, a CRM, a warmup tool, a support desk, or a second broadcast system, the list can spend another lookup. The mail that worked in June can fail in September because a helpful person added one include and did not recount.

RFC 7208 is the note that started this, and it is old. The lookup limit lives in the evaluation rules. The receiver does not keep resolving forever, because a hostile record could otherwise make DNS do unbounded work. Ten is the cap the standard sets. Mechanisms that trigger queries, including include and several others that look up hostnames, spend that budget. Nested includes spend it too, down the chain, not just on the first line you can read. When the count breaks the cap, the result is a permerror. A permerror is not a pass. DMARC, if it needed that SPF pass to align, does not get one from this record.

What is the SPF lookup limit?

RFC 7208 limits SPF evaluation to ten DNS lookups. Going past that is a permanent error, not a mild warning.

Ten feels like a lot until you watch a real record. One include for the broadcast platform can expand into several lookups of its own. Another include for the company that hosts the website's transactional mail spends more. A leftover include from a tool you canceled in 2024 still spends, because DNS does not know you meant to delete it. The record looks like diligence. The evaluation looks like a failure.

This is not a reason to fear SPF. It is a reason to count. A seller who last edited the record by pasting a vendor's "just add this include" line, and never flattened or checked the total, is one vendor away from a permerror on the day your solo ad needs the pass. The swipe will be blamed. The record will be the cause.

How does a normal sender hit the limit?

Each include, and several other mechanisms, can spend lookups. Adding another sending tool to a record that is already crowded can push it over ten.

The pattern on small lists is familiar. The owner starts on one platform. They add a second to "test deliverability." They add a form tool that sends its own receipts from the same domain. They add a personal mailbox host. Each vendor's help page shows a single include and calls the job done. Nobody adds the nested cost. The tenth lookup is crossed on a Tuesday when nothing about the offer changed, which is why the failure feels like a curse instead of arithmetic.

If you sell the send, check the count before you sell the week. If you are over, remove what you do not use or move a tool to a subdomain with its own record, and retest a real message. Do not add a warmup vendor to a broken record and hope engagement papers over a permerror. It will not. Safe solo ads sellers can tell you the record passes for the host that actually sends.

What should a solo ad buyer ask about SPF?

Ask whether the sending domain's SPF record evaluates to a pass for the server that will send, and ask when someone last checked the lookup count.

You are not asking them to paste the whole DNS zone into the chat. You are asking for a pass, a date, and the name of the host. A seller who checked this quarter will answer in a few lines. A seller who says SPF is "on" and cannot say when it was evaluated is describing a switch they have not looked at. The switch may already be a permerror.

Write the pass into the same quote as the from-name. If the live send fails SPF, the mail was not the authenticated send you bought. Buy solo ads from a domain whose permission list still fits in the ten lookups the standard allows. Helpful is only helpful if it still evaluates.