An SPF record can look short and still exceed its lookup budget. Here is what to count, what to document, and how to test a change without losing legitimate senders.
The limit is not ten sending services
SPF limits the evaluation of DNS-querying terms to ten. The terms include include, a, mx, ptr, exists, and redirect; nested evaluations count too. The ip4, ip6, and all mechanisms do not consume that budget. Exceeding the limit produces permerror, not an ordinary SPF fail. The standard also defines separate limits for some DNS processing. See RFC 7208, section 4.6.4.
Consider a fictional domain with three provider includes. Counting only those three entries misses the includes inside each provider’s policy. A useful audit follows the evaluation chain, rather than counting words in the TXT record. The path evaluated can depend on the sending address and mechanism order.
Start with a sender inventory
Create a worksheet with one row for each service: business mail, invoices, newsletters, website forms, and any old systems still sending notifications. Record the service owner, domain used for the envelope sender, whether DKIM is enabled, and a recent test-message result. A vendor name in the worksheet is not proof that its include still belongs in DNS.
Before removing an entry, ask the owner to demonstrate the workflow that uses it. A seasonal mailing service may be legitimate even when it has sent nothing this week. Keep the previous record and a change log so you can undo a mistake.
Reduce complexity, then test real messages
Look for retired providers and duplicated dependencies. Ask active providers whether they support a dedicated sending subdomain or another documented configuration. Do not copy a generic replacement record into production: each business has a different sender inventory.
Treat manual flattening as an ongoing maintenance commitment. If a provider changes its sending addresses, a copied list can become stale. Record who will monitor those changes before adopting that approach.
After the change, send representative messages from each workflow to external recipients. Capture the Authentication-Results header, the evaluated envelope domain, and the visible From domain. SPF alone does not establish that the visible sender is authenticated for DMARC; alignment still matters.
SBN can help inventory senders, review DNS, and document the test results through our SPF, DKIM, and DMARC services.
Need Expert Help?
Our team is ready to help protect and optimize your business technology. Get in touch for a free consultation.
Contact Us Today