07 / SPF calculator
Your SPF record gets 10 lookups.Count yours.
Too many DNS lookups in SPF is the most common reason a small business's invoices land in spam. Tick every service that sends mail as you. The calculator adds up the cost against the limit and drafts the record you would publish.
How the count works
SPF with too many DNS lookupsfails quietly.
A receiving server reads your SPF record and has to resolve every mechanism that points at another name. Each include:, a, mx, exists: and redirect= is one DNS query. An include also counts every query inside the record it pulls in. Google Workspace's include:_spf.google.com looks like one lookup and is actually four, because that record includes three more.
RFC 7208 caps the total at 10. On lookup 11 the receiver stops and returns permerror. Gmail, Outlook and most filters then treat the check as failed. Nothing bounces. Your mail just starts arriving in spam, often weeks after somebody added a new tool, which is why nobody connects the two.
The case we see most: Google Workspace at 4, then HubSpot at 2, Shopify at 2 and QuickBooks at 2, plus an a and an mx left over from a web host. That is 12. Add Mailchimp and it is 13. Each tool's setup screen told the owner to "add our include", and none of them mentioned the other three.
What to do when you are over
- Remove senders you stopped using. Old newsletter tools are the usual find.
- Drop
aandmxif your website and inbound mail servers never send outbound mail. They usually do not. - Move marketing mail to a subdomain such as
news.example-bakery.com, with its own SPF record and its own budget of 10. - Replace a stable include with its
ip4:ranges only if the provider publishes them as fixed. Most do not, and flattening by hand breaks silently when they change.
SPF is only one of the three. DKIM signs the message and has no lookup limit, and DMARC decides what happens when SPF or DKIM fails. A full SPF, DKIM and DMARC setup, with the MX records for Google Workspace, Microsoft 365 or Fastmail, is set out on the mail setup page.
Cutover
Lower the TTL first.Then wait.
The second block of the calculator answers one question: when can I change the record without half the internet still reading the old one?
A day. Common default at older registrars. A resolver that asked at 9:00 keeps the answer until 9:00 tomorrow, whatever you change in between.
An hour. A sensible resting value for MX and SPF on a small business domain.
Five minutes. Set it a full old-TTL before a cutover, switch, check, then raise it back to 3600.
The wait. Lowered a 86400 TTL six hours ago? You still have 18 hours before every cache has had to ask again.
Some resolvers ignore TTLs below 300 seconds or clamp very long ones. The formula gives the honest worst case for a resolver that follows the rules. Plan mail cutovers for a Friday afternoon, not a Monday morning.
Questions
Before you trustthe number.
Does this read my live DNS?
No. It adds up the costs you tick and type. Nothing leaves your browser. For the real count of your published record, send us the domain and we resolve it fully, nested includes and all.
Why does Google Workspace count as 4?
_spf.google.com includes three further records that list Google's netblocks. One include plus three nested ones. We measured it at the time of writing. Providers reshuffle these, so every cost in the tool is editable.
Can I just publish two SPF records?
No. Two TXT records starting with v=spf1 on the same name is itself a permerror. One record per name, always. Use a subdomain if you need a second budget.
Should I end with -all or ~all?
Use ~all while you are still finding senders, and let DMARC at p=none report who is missing. Move to -all once the reports have been clean for two weeks.
Is the calculator a quote?
No. It is an estimate of a record. Our prices are on the services page, and the written quote after we look at the domain is what counts.