XiaTools

How to Flatten an SPF Record to Reduce DNS Lookups

Updated 11 Oct 2026

An SPF record flattening technique replaces mechanism names like include: with their corresponding static IP addresses, reducing the total number of dynamic DNS queries your mail receivers must perform. When domain administrators add too many third-party email services, their Sender Policy Framework record easily exceeds the strict RFC-mandated limit of 10 DNS lookups, causing legitimate emails to fail authentication. By turning dynamic lookups into hardcoded IP blocks, you ensure your outbound mail reliably passes authentication checks across all major inbox providers.

To see how your current configuration stands, you can use the SPF Checker tool to instantly audit your domain, count your exact lookup consumption, and identify bloated includes before they break your mail flow.

Understanding the SPF 10-Lookup Limit

The Sender Policy Framework relies on DNS TXT records to publish which mail servers are authorized to send email on behalf of a domain. The protocol specification strictly limits mechanisms that trigger recursive DNS lookups to a maximum of 10 per evaluation.

Mechanisms that consume a lookup include:

  • include:
  • a
  • mx
  • ptr (deprecated)
  • exists
  • redirect

Mechanisms like ip4 and ip6 do not trigger recursive lookups because the IP addresses are explicitly defined inside the record itself. When a receiving mail server processes an unflattened record containing multiple nested include: statements, it traverses the DNS tree until it hits the limit. If the traversal exceeds 10 queries, the evaluation immediately halts with a permerror (Permanent Error), and receiving mail servers typically reject the message or send it straight to the spam folder.

How SPF Record Flattening Works

Flattening converts dynamic hostname references into static IP addresses. Instead of telling the receiving server to ask Google or Mailgun what their current IPs are (include:_spf.google.com), your flattened record explicitly lists those exact IPv4 and IPv6 blocks (ip4:172.217.0.0/16, etc.).

Before Flattening (Dynamic & Risky)

v=spf1 include:_spf.google.com include:mail.example.com include:spf.protection.outlook.com ~all
  • v=spf1: Defines the protocol version.
  • include:_spf.google.com: Consumes multiple lookups internally.
  • include:mail.example.com: Consumes 1 lookup.
  • include:spf.protection.outlook.com: Consumes multiple lookups internally.
  • ~all: SoftFail policy for unlisted servers.

After Flattening (Static & Safe)

v=spf1 ip4:192.0.2.1/32 ip4:192.0.2.128/25 ip6:2001:db8::/32 ~all

By resolving all underlying domains recursively and compiling their exact IP ranges into concise CIDR blocks, you reduce your DNS lookup count from an unpredictable number (often 12 to 15+) down to zero.

Step-by-Step Guide to Manual SPF Flattening

If you prefer to flatten your domain's authentication policy manually rather than using an automated service, follow this structured operational workflow.

Step 1: Audit Your Current Record

Query your existing public DNS configuration using command-line utilities to inspect your live TXT record.

nslookup -type=txt example.com

Alternatively, use dig on Linux and macOS environments:

dig example.com TXT +short

Step 2: Resolve Nested Includes

Take every domain listed inside an include: mechanism and find its associated IP addresses. For example, if your record includes _spf.google.com, query its sub-records until you extract all CIDR blocks. You can query A and AAAA records for subdomains using PowerShell:

Resolve-DnsName -Name _spf.google.com -Type TXT

Step 3: Consolidate and Minimize CIDR Blocks

Group the gathered IP addresses logically. Combine adjacent IP ranges into efficient CIDR notation to save character space, keeping in mind the strict 255-character limit of a single DNS TXT string chunk.

Step 4: Publish the Flattened Record

Log into your DNS hosting provider's management console. Navigate to your domain's DNS zone editor (menu paths vary by provider, typically labeled as DNS Settings, Zone Management, or Manage DNS). Update your existing TXT record where the host is @ or blank, paste your new flattened string, and set an appropriate TTL (Time To Live) such as 3600 seconds.

Comparing SPF Management Strategies

Strategy Pros Cons Lookup Count Risk Level
Standard Includes Automatically updates when vendors change IPs Prone to breaking when vendors add servers Variable (Often > 10) High
Manual Flattening Zero lookups, complete control Requires regular manual audits and updates 0 Medium
Automated Flattening Zero lookups, auto-syncs with vendor changes Relies on third-party SaaS management tools 0 Low

Common Mistakes and How to Fix Them

Transitioning to a flattened record introduces unique operational traps. Avoid these common pitfalls to maintain uninterrupted email delivery.

  • Exceeding the 255-Character TXT Limit: Traditional DNS specifications limit a single text string inside a TXT record to 255 characters. If your flattened IP list is long, split the record into multiple quoted strings separated by a space (e.g., "v=spf1 ip4:192.0.2.1 ..." "ip4:192.0.2.2 ... ~all"). Modern DNS providers often handle string chunking automatically.
  • Failing to Update When Vendors Change IPs: Third-party providers like marketing platforms or CRM tools frequently rotate their sending infrastructure. If you manually flatten your record and your vendor changes their IP ranges, your outgoing emails will fail. Set up calendar reminders to re-audit your vendor blocks quarterly.
  • Retaining Obsolete Includes: Administrators often forget to remove old include: statements after flattening, accidentally leaving redundant mechanisms in the record alongside the new hardcoded IPs.

SPF Flattening Checklist

Use this quick checklist before deploying your updated DNS configuration:

  • Audited all third-party email services currently sending on behalf of your domain.
  • Resolved every nested include:, a, and mx mechanism to its base IPv4 and IPv6 CIDR blocks.
  • Confirmed the total DNS lookup consumption equals zero or stays safely below 10.
  • Verified that the total character length complies with DNS TXT string limits.
  • Published the updated TXT record in your DNS provider zone.
  • Verified mail delivery and policy evaluation using an external lookup tool.

Frequently asked questions

What happens if my SPF record exceeds 10 DNS lookups?

When a receiving mail server evaluates an SPF record and exceeds the 10-lookup threshold, it stops processing immediately and returns a permanent error (permerror). Depending on the receiving server's strictness policy, your email will either be outright rejected during the SMTP handshake or diverted directly to the recipient's spam folder.

Is manual SPF flattening safe if third-party vendors change their IPs?

Manual flattening is safe only if you establish a strict maintenance schedule to review and update your IP blocks regularly. Because third-party vendors update their infrastructure without notifying you, static IP addresses can become outdated, causing legitimate emails to fail authentication.

Does SPF record flattening support IPv6 addresses?

Yes, flattening supports both IPv4 and IPv6 addresses. When you extract IP blocks from nested includes, you must include both `ip4:` and `ip6:` CIDR notations to ensure complete authentication coverage for modern mail servers.

How does automated SPF flattening differ from manual flattening?

Automated flattening uses a specialized service to dynamically monitor your vendor's include statements in real time and publish an updated, flattened set of static IP addresses to your DNS provider. This eliminates the need for manual quarterly audits while keeping your lookup count at zero.

Can I use multiple TXT records for SPF on the same domain?

No, you must never publish more than one SPF TXT record for a single domain. If a receiving mail server encounters multiple valid SPF records during a lookup, it considers the configuration ambiguous and treats the policy as invalid, causing all your emails to fail authentication.

Related articles

Free tools