A customer rings to ask why nobody replied to their enquiry. You did reply, four days ago, and twice since. All three messages are sitting in their junk folder. Nothing has changed at your end, nobody has touched your DNS in two years, and your SPF record is still there looking perfectly sensible.
It very likely stopped working months ago, and nothing would have told you.
What SPF Is Actually For
SPF is a short public record in your domain’s DNS listing the systems allowed to send email using your name. Microsoft 365 is usually in there. So is whatever sends your invoices, your quoting tool, your newsletter platform, your remote monitoring software. When a message arrives claiming to come from you, the receiving mail server reads that list and checks whether the message came from one of them.
That is the whole idea, and it works well enough that almost every business domain in the country now has one. The trouble is in how the list gets read.
Why There Is a Limit at All
Reading an SPF record is not a single lookup. Each entry that names another provider sends the receiving server off to fetch that provider’s own record, and those records contain entries of their own, which send it off again. One line in your record can quietly become five or six separate queries before the server has finished.
Left unchecked, that is a convenient way to make one small request generate a great deal of traffic against somebody else, so the specification caps the whole exercise at ten lookups. Ten is a hard ceiling rather than a target, and it counts everything nested underneath.
How a Record Drifts Over the Line
Nobody sits down and writes a record with nineteen lookups in it. They write one with four, and then the business carries on.
A new accounting package arrives and the supplier says to add a line. The marketing agency needs one for the newsletter. Somebody buys an email signature tool. Each addition is a single line, each request is reasonable, and each is approved by a different person months apart. Nobody is counting, because there is nothing obvious to count.
We looked at an entirely ordinary record recently with five entries in it: Microsoft, an accounts platform, a monitoring tool, a signature service and the mail filter. Following all five down to the bottom came to nineteen lookups. One of those five was responsible for nine on its own, because that provider’s record chained out to a marketing platform, a support desk and two further internal records. Nothing about the record looked wrong. It had been failing for a long time.
What Happens When You Cross It
This is the part that catches people out. The record is not trimmed to the first ten entries with the rest ignored. The whole check is abandoned.
A receiving server that runs out of lookups returns a permanent error, and in practice almost everything treats that the same as an outright failure. Every entry you listed is discarded, including all the correct ones. A domain with a long, carefully maintained SPF record ends up in precisely the same position as a domain with no record at all.
What that costs you depends on what else you have published. If your DMARC policy is set to quarantine or reject, which is where you should be heading, you have instructed the world to junk or refuse mail that fails authentication, and your own mail now fails authentication. Quotes stop arriving. Invoices stop arriving. Nobody tells you, because from your side everything looks sent.
If you have no DMARC record at all, the effect is quieter and arguably worse. None of your mail gets junked, but you have none of the protection you believed you had, and anyone who fancies it can send email in your name. That is the usual opening move in the sort of invoice fraud we wrote about in Business Email Compromise.
Either way, nothing in your mailbox, your DNS control panel or your Microsoft tenant will mention any of it.
Finding Out, and Putting It Right
The fix is usually subtraction rather than addition, which makes it cheaper than people expect. Most records that are over the limit are carrying entries for services the business stopped using years ago. The newsletter platform they moved off in 2023. The CRM that was replaced. Taking those out costs nothing and is often enough on its own.
Where a sender is genuinely needed but expensive, it is sometimes possible to swap a broad entry for the narrower one that actually applies to you. Replacing entries with raw IP addresses, a practice usually called flattening, does bring the number down, but those addresses belong to somebody else and change without telling you, so you are committing to maintain it indefinitely. It is a reasonable last resort and a poor first one.
Once the record sits comfortably inside the limit and every legitimate sender is passing, DMARC can be moved up to quarantine and then to reject. That is the point at which the whole arrangement starts protecting you rather than merely describing you.
Checking Your Own
You can count it by hand, which is tedious and easy to get wrong, or you can use our email security checker. It follows every entry down through the chain, gives you the total, and tells you your DMARC policy and whether DKIM is signing while it is there. It takes about ten seconds and asks for nothing.
If the number comes back above ten, it is worth sorting out this week rather than next quarter. And if you are not certain what is safe to remove, ask us before you start deleting lines.





