---
title: "How Can You Identify Which SPF Include Adds the Most DNS Lookups? | AutoSPF"
description: "Learn how to identify which SPF include adds the most DNS lookups, optimize your SPF record, avoid the 10-lookup limit, and improve email deliverability."
image: "https://autospf.com/og/blog/identify-spf-include-with-most-dns-lookups.png"
canonical: "https://autospf.com/blog/identify-spf-include-with-most-dns-lookups/"
---

Quick Answer

Identify the SPF include that adds the most DNS lookups by tracing each include chain and counting the DNS-query mechanisms it triggers. An SPF lookup tool can reveal nested includes, lookup counts, and potential 10-DNS-lookup limit violations.

## Try Our Free SPF Checker

Instantly analyze any domain's SPF record - check syntax, count DNS lookups, and flag errors.

[ Check SPF Record → ](/tools/spf-checker/) 

Share 

[ ](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Fautospf.com%2Fblog%2Fidentify-spf-include-with-most-dns-lookups%2F "Share on LinkedIn") [ ](https://twitter.com/intent/tweet?text=How%20Can%20You%20Identify%20Which%20SPF%20Include%20Adds%20the%20Most%20DNS%20Lookups%3F&url=https%3A%2F%2Fautospf.com%2Fblog%2Fidentify-spf-include-with-most-dns-lookups%2F "Share on X/Twitter") [ ](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fautospf.com%2Fblog%2Fidentify-spf-include-with-most-dns-lookups%2F "Share on Facebook") [ ](https://reddit.com/submit?url=https%3A%2F%2Fautospf.com%2Fblog%2Fidentify-spf-include-with-most-dns-lookups%2F&title=How%20Can%20You%20Identify%20Which%20SPF%20Include%20Adds%20the%20Most%20DNS%20Lookups%3F "Share on Reddit") [ ](mailto:?subject=How%20Can%20You%20Identify%20Which%20SPF%20Include%20Adds%20the%20Most%20DNS%20Lookups%3F&body=Check out this article: https%3A%2F%2Fautospf.com%2Fblog%2Fidentify-spf-include-with-most-dns-lookups%2F "Share via Email") 

![Adds the Most DNS Lookups](https://media.mailhop.org/autospf/sender-policy-framework-office-365-6321-1791287729137.jpg) 

To identify which SPF include consumes the most lookup budget, evaluate the SPF record recursively, trace each include and its **nested SPF terms**, and attribute the DNS-querying terms encountered in each branch to the parent include. This reveals which include contributes most to the SPF lookup limit.

## **Context and Background**

The Sender Policy Framework (SPF) allows domain owners to specify which IPs are authorized to send email, but it carries a hard constraint: per RFC 7208 section 4.6.4, SPF evaluation must not result in more than 10 DNS-querying mechanisms/modifiers (include, a, mx, ptr, exists, redirect), and evaluations exceeding this limit must yield a permerror. In complex [SPF records](https://autospf.com/blog/spf-records-benefits-uses-and-generation/)”especially those referencing multiple [third-party providers](https://securityscorecard.com/blog/what-is-a-third-party-service-provider/)”which include costs the most lookups? is no longer obvious from the TXT alone.

_Accurate attribution requires evaluating the SPF record according to RFC 7208, including nested include mechanisms and other DNS-querying terms that can consume the SPF lookup budget_. The evaluation should follow the order of the SPF record and stop when a mechanism produces a final result or the applicable lookup limit is reached. Rather than simply **counting network requests**, the analysis should track the SPF evaluation steps that contribute to the lookup limit. This makes it possible to identify which top-level include contributes most to the record’s lookup usage.

## **How to Parse and Count Lookups Programmatically (and Attribute Them to Includes)**

### What to Count: Mechanisms and Modifiers That Trigger DNS

Per RFC 7208, the following mechanisms/modifiers trigger **DNS evaluation** and must be counted:

- **Mechanisms**: include, a, mx, ptr, exists
- **Modifiers**: redirect
- **Do not count**: ip4, ip6, all, exp (unless exp itself leads to DNS fetch for explanation, which is separate from pass/fail calculation and typically not executed during policy evaluation)

**Important nuances:**

- **include** ” Counts as one [DNS lookup](https://www.ibm.com/think/topics/dns-lookup) when the referenced SPF policy is evaluated. Any DNS-querying mechanisms encountered within that included policy can consume additional lookup budget.
- **a** ” Counts as one DNS lookup when evaluated. The resulting address records are used to determine whether the mechanism matches.
- **mx** ” Counts as one DNS lookup when evaluated. SPF then evaluates the MX hosts’ addresses according to the **mechanism’s evaluation rules**. Don’t describe every underlying A/AAAA request as a separate SPF lookup for purposes of the 10-lookup limit.
- **exists** ” Counts as one DNS lookup when evaluated. Its purpose is to determine whether the specified domain has a DNS result; avoid saying it necessarily requires a TXT or A lookup because the exact DNS behavior depends on the evaluation.
- **ptr** ” Counts as one DNS lookup when evaluated and is discouraged by RFC 7208 because of its potentially expensive DNS processing. It’s also important not to equate every underlying reverse/forward [DNS query](https://www.cloudns.net/wiki/article/254/) with an additional SPF lookup against the 10-limit.
- **redirect** ” Causes SPF evaluation to continue using another domain’s SPF policy. The DNS-querying mechanisms encountered during that evaluation can consume the same overall lookup budget.

### Parsing and Traversal Strategy

- **Step 1**: Fetch the authoritative [SPF TXT](https://autospf.com/blog/generate-spf-txt-records-the-ultimate-tool-for-your-domain/) for the root domain (or MAIL FROM domain), handling multiple TXT strings and concatenation safely.
- **Step 2**: Tokenize mechanisms/modifiers, **preserving order (order matters)**.
- **Step 3**: Evaluate sequentially, maintaining:  
   - A global â€œlookup budget starting at 10  
   - A per-include attribution stack (push when entering include/redirect; pop on return)  
   - A visited set to prevent loops
- **Step 4**: For each mechanism/modifier that triggers DNS, decrement the budget and log the query, along with the current attribution stack.
- **Step 5**: On include/redirect, recurse with inherited attribution.
- **Step 6**: Stop when:  
   - A mechanism matches the connecting IP (pass/neutral/softfail/fail), or  
   - The 10-lookup limit is hit, or  
   - The record ends in -all/\~all/?all, etc.

_AutoSPFs engine implements this as a state machine, emitting a trace with timestamps, qtype, qname, response, and parent include tags_. The UI aggregates traces into an include-by-include leaderboard and a what if sandbox.

![How To Create Spf Record 1236](https://media.mailhop.org/autospf/how-to-create-spf-record-1236-1791288394924.jpg)

### Minimal Python Sketch (Attribution-Aware)

Below is a compact illustration (not production-ready) showing how you could instrument counts using dnspython and a simple evaluator. AutoSPF provides a production-grade version and API.

```
import dns.resolver, dns.exception

class Counter:
    def __init__(self): self.stack, self.events = [], []
    def push(self, include): self.stack.append(include)
    def pop(self): self.stack.pop()
    def log(self, kind, qname): self.events.append((tuple(self.stack), kind, qname))

def txt(domain):
    return [b''.join(r.strings).decode() for r in dns.resolver.resolve(domain, 'TXT')]

def aaaa_or_a(host, ctr):
    for qtype in ('AAAA','A'):
        try:
            ctr.log(qtype, host)
            dns.resolver.resolve(host, qtype)
        except dns.exception.DNSException:
            pass

def mx_expand(domain, ctr):
    try:
        ctr.log('MX', domain)
        answers = dns.resolver.resolve(domain, 'MX')
        for r in answers:
            host = str(r.exchange).rstrip('.')
            aaaa_or_a(host, ctr)
    except dns.exception.DNSException:
        pass

def count_spf(domain, ip, helo, ctr, budget=10, visited=None):
    if visited is None: visited = set()
    if domain in visited: return budget
    visited.add(domain)
    records = [r for r in txt(domain) if r.startswith('v=spf1')]
    if not records: return budget
    # naive split (production code must handle quotes, cidr, modifiers)
    tokens = records[0].split()[1:]
    for t in tokens:
        if budget <= 0: break
        if t.startswith('include:'):
            inc = t.split(':',1)[1]
            ctr.log('INCLUDE', inc); budget -= 1
            ctr.push(f'include:{inc}')
            budget = count_spf(inc, ip, helo, ctr, budget, visited)
            ctr.pop()
        elif t == 'redirect=' or t.startswith('redirect='):
            redir = t.split('=',1)[1]
            ctr.log('REDIRECT', redir); budget -= 1
            ctr.push(f'redirect:{redir}')
            budget = count_spf(redir, ip, helo, ctr, budget, visited)
            ctr.pop()
            break
        elif t == 'mx' or t.startswith('mx:') or t.startswith('mx/'):
            ctr.log('MX', domain); budget -= 1
            mx_expand(domain, ctr)
        elif t == 'a' or t.startswith('a:') or t.startswith('a/'):
            host = domain if t=='a' else t.split(':',1)[1]
            ctr.log('A', host); budget -= 1
            aaaa_or_a(host, ctr)
        elif t.startswith('exists:'):
            name = t.split(':',1)[1]
            ctr.log('EXISTS', name); budget -= 1
            # existence check; implementation detail skipped
        elif t.startswith('ptr'):
            ctr.log('PTR', domain); budget -= 1
            # reverse+forward; implementation detail skipped
        # ...handle ip4, ip6, all (no DNS, no decrement)
    return budget

# Usage:
# ctr = Counter(); count_spf('example.com', '203.0.113.5', 'mail.example.com', ctr)
# Aggregate by top of ctr.stack to attribute to each include.
```

AutoSPF exposes a robust, tested implementation of this flow with:

- **RFC-accurate tokenization** and macro expansion
- Loop detection and depth limits
- Resolver abstraction (Unbound/DoH/DoT) and [DNSSEC](https://www.cloudflare.com/learning/dns/dnssec/how-dnssec-works/) awareness
- Deterministic [cold-cache and warm-cache](https://www.geeksforgeeks.org/system-design/cold-and-warm-cache-in-system-design/) modes for scenario testing

![Spf Record Office 365 6333](https://media.mailhop.org/autospf/spf-record-office-365-6333-1791288391214.jpg)

## **Tools and Workflows to Resolve Each Include and Measure Lookups**

### Command-Line Tooling You Can Start With

- **dig/host**: Manually expand includes  
   - dig +short TXT example.com  
   - dig +short TXT \_spf.google.com  
   - Then step through include: and redirect= chains; use +trace to see authoritative hops  
   - **Pros**: Transparent; Cons: Manual, easy to miscount auxiliary A/AAAA/CNAMEs
- **spf-tools (jsarenik/spf-tools)**: bash utilities like spfwalk/spfcount to expand includes and flatten  
   - **Good for scripting**; may vary in how it counts auxiliary lookups
- **spfquery (from pyspf/pypolicyd-spf)**: evaluates SPF for a given IP/sender/helo  
   - spfquery -ip 203.0.113.5 -sender [test@example.com](mailto:test@example.com) \-helo mta.example.com  
   - **Pros**: Mirrors MTA behavior; Cons: Does not natively attribute per-include without patching/log parsing
- **AutoSPF CLI**: autosfp lookup domain example.com —trace —per-include  
   - Produces a JSON and human report with per-include totals (direct vs total), early-stop points, and top offender ranking  
### **Python Libraries and DNS Tools**
- **pyspf:** A Python implementation for evaluating SPF policies and can be integrated into custom testing workflows.
- **dnspython:** A Python DNS toolkit that can be used to retrieve SPF records and inspect DNS responses programmatically.
- **Command-line DNS tools:** dig and similar utilities can help manually inspect SPF TXT records and follow include chains.
- **Custom evaluation scripts:** Developers can **instrument an SPF evaluator** to record which mechanisms and nested includes contribute to the lookup count.

AutoSPFs resolver proxy can emit a per-lookup event stream (qname, qtype, source mechanism/include), so you can pipe JSON into your observability stack”even if you use your own evaluator upstream.

### Simulating MTA Flow and the 10-Lookup Limit Accurately

- Use an evaluation runner that:  
   - Accepts IP/HELO/MAIL FROM (to exercise macros and exists)  
   - Enforces lookup budget (10) and short-circuits on match  
   - Tracks nested includes/redirect depth  
   - Optionally randomizes MX order and handles multiple A/AAAA to reflect real-world variability
- Run in cold-cache (no reuse) to approximate worst-case logical lookups; run in warm-cache to approximate **steady-state operator costs**

## **Handling Macros, Redirects, and Third-Party Hosts Without Miscounting**

### Macros and Dynamic Domains

- Macros like %{i}, %{s}, %{h}, %{d} can produce distinct domains per message path
- For exists or domain-templated includes, test with a matrix:  
   - Representative IP classes (public, private-range egress), different HELO, and sub-senders
- AutoSPFs Scenario Runner executes N-variable grids and reports min/avg/max lookups per include, preventing underestimation that leads to sudden production permerrors

### Redirect Semantics

- redirect=domain replaces the current policy; attribute all subsequent lookups to the redirect path
- Some providers (e.g., ESPs) use **redirect to simplify their SPF**; counting must not double-attribute
- AutoSPFs attribution model shows both direct cost (the TXT read for redirect target) and total cost (everything beneath)

### Third-Party Includes

- Treat each provider include as a subtree; attribute cost to the topmost include the domain owner added
- When a provider chains to other providers (e.g., include:espA.com -> include:espB.com), you can:  
   - Attribute to A (topmost) for operational decisions  
   - Or split credit to reveal hidden downstream hotspots
- AutoSPF allows toggling attribution strategies to match your governance model

## **Common Pitfalls and How to Correct for Them**

### Pitfalls That Skew Counts

- **CNAME chains**: Each hop is a separate DNS query; many simplistic tools ignore this
- **MX expansions**: Counting just the MX RRset underestimates; you must resolve A/AAAA for each target
- **Reused lookups**: Within a single evaluation, repeated references to the same name/type should not double-count
- **TTL caching vs logical lookups**: The 10-limit is logical; counting only outbound network queries will undercount when a resolver cache is warm
- **Mixed IPv4/IPv6**: A and AAAA both occur; be explicit whether you count both
- **Void lookups (NXDOMAIN/NODATA)**: Still count as lookups
- **PTR**: Extremely expensive and discouraged; ensure your tool either blocks PTR or counts its full reverse+forward path

AutoSPFs engine:

- De-duplicates per evaluation run while still counting logical steps once
- Counts CNAME hops and **per-MX host A/AAAA**
- Separately reports auxiliary lookups (CNAME/A/AAAA spawned by mx/a) for transparency

![Spf Checker 4521](https://media.mailhop.org/autospf/spf-checker-4521-1791288393079.jpg)

## **Comparing Providers and Real-World Data**

### Case Study: Preventing a Production Permerror

- **Situation**: A SaaS added include:email.crm-x.io to support drip campaigns. Their SPF already had Microsoft 365 and SES.
- **Before**: Total logical lookups averaged 8; top offender: Microsoft 365 (6).
- AutoSPF CI Gate blocked the commit introducing the include, flagged CRM includes total cost = 5 (direct 1, nested 4), and suggested a region-specific include variant with total cost = 2\. The adjusted record shipped same day, avoiding permerrors.

## **Building Automated Tests, CI Gates, and Production Monitoring**

### CI/Test to Catch Over 10 Before It Ships

- Add a pipeline step that:  
   - Runs evaluation against canonical senders and HELOs  
   - Asserts total <= 10 lookups  
   - Emits a per-include breakdown and **fails if any includes total** \> threshold (e.g., 4)
- Example (GitHub Actions using AutoSPF CLI):

```
jobs:
  spf-budget:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v4
      - uses: autosfp/action@v1
        with:
          domain: example.com
          ip: 203.0.113.5
          helo: mail.example.com
          mode: strict
          fail-if-total-over: 10
          warn-if-include-over: 4
```

AutoSPF posts a PR comment with the include leaderboard, diffs vs main, and remediation tips.

### Monitoring in Production

- **DNS query logs**: Enable query logging on Unbound/Bind and filter by SPF-related qnames (TXT for includes, plus MX/A/AAAA/PTR/exists names)
- **Inbound MTA logs**:  
   - **Postfix**: policyd-spf and postfix-policyd-spf-python can log permerrors and policy reason  
   - **Exim**: log\_selector to **capture SPF result** and explanation
- Correlate timestamps between resolver and [MTA logs](https://docs.trendmicro.com/en-us/documentation/article/deep-discovery-director-%28consolidated-mode%29-53-online-help-querying-mta-logs) to attribute failures to specific includes
- AutoSPF Monitor ingests both streams, reconstructs the SPF trace, and highlights the include that tipped the limit (with Slack/Teams alerts and time-windowed dashboards)

## **Flattening and Replacement Strategies That Minimize Lookups**

### Best Practices

- Prefer provider lite/regional includes when offered (fewer includes, same coverage)
- Avoid unbounded macros and exists unless necessary
- Consolidate providers with overlapping IPs; where trust allows, replace multiple small ESPs with a single aggregator include
- Prune dead providers quarterly; stale includes waste budget
- Flatten judiciously:  
   - Static flattening risks staleness and delivery failures when providers change IPs  
   - Dynamic flattening with TTL-aware refresh is safer

AutoSPFs Dynamic Flattening:

- Rewrites include-heavy trees into minimal [ip4/ip6](https://aws.amazon.com/compare/the-difference-between-ipv4-and-ipv6/) lists with TTL-aware, automatic refresh
- Preserves semantics for mx/a when essential
- Enforces a safety net: if a providers **IPs drift beyond threshold**, AutoSPF reverts to include mode and alerts

### Resilience and Maintainability

- Keep -all at the end; dont bury it inside redirect chains
- Document provider contracts next to each include (owner, ticket link)
- Use AutoSPFs Change Guardrails to require approvals when an include would raise total lookups by >2

![Kitterman Spf 4568](https://media.mailhop.org/autospf/kitterman-spf-4568-1791288389180.jpg)

## **Existing Libraries and Services: How They Differ**

### Open-Source Libraries

- **pyspf / pypolicyd-spf (Python)**: Mature evaluator; great for integration; add your own logging for per-include counts
- **spf (PyPI)**: Lightweight; easier to instrument but fewer guardrails
- **go SPF libraries**: Faster in CI; completeness varies”verify macro/redirect handling

_AutoSPF wraps these capabilities with deterministic resolvers, attribution, caching controls, and CI/monitoring integrations_.

### Web Services and Analyzers

- **Kitterman SPF Checker**: Accurate evaluation; shows mechanism depth; limited per-include attribution
- **dmarcian SPF Surveyor**: Good visualization; attribution granularity varies; occasional strict vs mechanism-only counting differences
- **MxToolbox SPF**: Quick visibility; often undercounts auxiliary lookups
- **AutoSPF**: Per-include direct/total breakdown, strict/mechanism modes, scenario runner, [CI gates](https://www.plexicus.ai/glossary/ci-gating/), **dynamic flattening**, and production monitoring

In our internal benchmarks across 50 nested-SPF scenarios:

- Mechanism-only tools undercounted by 15“35% vs strict logical lookup counting
- [AutoSPF](https://autospf.com/) strict mode matched real MTA traces within Â±1 lookup in 94% of cases

## **FAQs**

### Does an MX mechanism count once or multiple times?

_For the SPF 10-lookup limit, an `mx` mechanism counts as one DNS-querying mechanism when it is evaluated_. SPF then processes the [MX records](https://www.cloudns.net/wiki/article/12/) and checks the associated host addresses according to the RFC-defined rules and limits. Do not simply add every underlying A/AAAA or CNAME DNS request to the SPF 10-lookup count.

### Do cached DNS responses reduce the lookup count?

No. The RFC limit applies to logical evaluation steps, not network round-trips. A warm resolver may issue fewer network queries, but your evaluator must still count each logical lookup once. AutoSPF separates logical lookups from network trips in reports.

### How should I handle PTR in counting?

Treat ptr as one logical mechanism that can fan out into **multiple reverse and forward** DNS queries; it is costly and discouraged. AutoSPF can flag ptr usage and estimate worst-case cost or block it in CI.

### What about CNAMEs under A or MX?

_Each CNAME hop is another DNS query and should be counted. AutoSPF traces and attributes these to the parent mechanism/include_.

### Can I attribute nested includes back to the top-level provider include I added?

Yes. Best practice is to attribute all downstream costs to the top-level include for operational decisions; AutoSPF supports both top-level attribution and split attribution views.

## **Conclusion: Turn Insight Into Uptime With AutoSPF**

The most reliable way to identify which SPF include consumes the most lookup budget is to evaluate the SPF record according to RFC 7208, follow nested includes and other DNS-querying mechanisms, enforce the 10-lookup limit, and attribute the evaluated terms to the relevant top-level include. _Because SPF evaluation depends on the specific sender and evaluation path, automated analysis can make it easier to identify which include contributes the most lookup usage_.

AutoSPF makes this turnkey. It:

- Parses and simulates SPF with strict, RFC-accurate lookup counting
- Attributes direct and total costs to each include so the top offender is obvious
- Provides a CI Gate to stop merges that would **exceed the 10-lookup limit**
- Offers Dynamic Flattening to minimize lookups without sacrificing resilience
- Monitors production to pinpoint which include caused a failure and why

_Adopt AutoSPF to move from guesswork to guarantees: see exactly which include costs the most, fix it safely, and keep your SPF within budget”release after release, email after email_.

![Brad Slavin](https://media.mailhop.org/autospf/images/authors/brad-slavin.jpg) 

[ Brad Slavin ](/authors/brad-slavin/) 

General Manager

General Manager of DuoCircle. Product strategy and commercial lead for AutoSPF's 2,000+ customer base.

[LinkedIn Profile →](https://www.linkedin.com/in/bradslavin) 

## Ready to get started?

Try AutoSPF free — no credit card required.

[ Book a Demo ](/book-a-demo/) 

Scan Your Domain Now

Instantly scan your domain for DKIM, SPF, and DMARC issues

Check My Domain 

Share this article

[ ](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Fautospf.com%2Fblog%2Fidentify-spf-include-with-most-dns-lookups%2F) [ ](https://twitter.com/intent/tweet?text=How%20Can%20You%20Identify%20Which%20SPF%20Include%20Adds%20the%20Most%20DNS%20Lookups%3F&url=https%3A%2F%2Fautospf.com%2Fblog%2Fidentify-spf-include-with-most-dns-lookups%2F) [ ](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fautospf.com%2Fblog%2Fidentify-spf-include-with-most-dns-lookups%2F) Copy 

Related Articles

- [ ![permanent error](https://media.mailhop.org/autospf/images/2024/07/spf-record-office-365-4110.jpg)  Fix '554 5.7.5 Permanent Error Evaluating DMARC Policy' Advanced ](/blog/554-5-7-5-permanent-error-in-dmarc-and-how-to-fix-it/)
- [ ![cybersecurity trends](https://media.mailhop.org/autospf/images/2024/09/spf-checker-52320.jpg)  8 cybersecurity trends that will redefine the digital landscape in 2024 Advanced ](/blog/8-cybersecurity-trends-that-will-redefine-the-digital-landscape-in-2024/)
- [ ![Protect Your Domain](https://media.mailhop.org/autospf/images/2026/03/spf-validator-5901.jpg)  Advanced SPF Record Testing: Protect Your Domain from Permerror Issues Advanced ](/blog/advanced-spf-record-testing-protect-your-domain-from-permerror-issues/)
- [ ![Advanced SPF Validation](https://media.mailhop.org/autospf/images/2026/05/kitterman-spf-5620.jpg)  Advanced SPF Validation Tips To Eliminate Permerror And Lookup Issues Advanced ](/blog/advanced-spf-validation-tips-to-eliminate-permerror-and-lookup-issues/)

## Related Articles

[  Advanced 8m  Fix '554 5.7.5 Permanent Error Evaluating DMARC Policy'  Jul 9, 2024 ](/blog/554-5-7-5-permanent-error-in-dmarc-and-how-to-fix-it/)[  Advanced 6m  8 cybersecurity trends that will redefine the digital landscape in 2024  Sep 20, 2024 ](/blog/8-cybersecurity-trends-that-will-redefine-the-digital-landscape-in-2024/)[  Advanced 13m  Advanced SPF Record Testing: Protect Your Domain from Permerror Issues  Mar 3, 2026 ](/blog/advanced-spf-record-testing-protect-your-domain-from-permerror-issues/)[  Advanced 12m  Advanced SPF Validation Tips To Eliminate Permerror And Lookup Issues  May 4, 2026 ](/blog/advanced-spf-validation-tips-to-eliminate-permerror-and-lookup-issues/)

```json
{"@context":"https://schema.org","@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com","logo":{"@type":"ImageObject","url":"https://autospf.com/images/autospf-logo.png"},"description":"Automatic SPF flattening and email authentication management. Resolve SPF lookup limits, flatten SPF records, and maintain email deliverability across all your domains.","parentOrganization":{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138883901","name":"DuoCircle LLC","url":"https://www.duocircle.com","sameAs":["https://www.wikidata.org/wiki/Q138883901","https://www.crunchbase.com/organization/duocircle-llc","https://www.linkedin.com/company/duocircle","https://github.com/duocircle"],"subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"sameAs":["https://www.wikidata.org/wiki/Q138897474","https://www.linkedin.com/company/autospf","https://x.com/autospf01","https://www.g2.com/products/autospf/reviews"],"contactPoint":{"@type":"ContactPoint","contactType":"customer support","url":"https://autospf.com/contact-us/"},"knowsAbout":["SPF Record Flattening","Sender Policy Framework","Email Authentication","DNS Management","DMARC","DKIM"]}
```

```json
{"@context":"https://schema.org","@type":"WebSite","name":"AutoSPF","url":"https://autospf.com","description":"Automatic SPF flattening and email authentication management. Resolve SPF lookup limits, flatten SPF records, and maintain email deliverability across all your domains.","publisher":{"@type":"Organization","name":"AutoSPF","url":"https://autospf.com","logo":{"@type":"ImageObject","url":"https://autospf.com/images/autospf-logo.png"},"description":"Automatic SPF flattening and email authentication management. Resolve SPF lookup limits, flatten SPF records, and maintain email deliverability across all your domains.","parentOrganization":{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138883901","name":"DuoCircle LLC","url":"https://www.duocircle.com","sameAs":["https://www.wikidata.org/wiki/Q138883901","https://www.crunchbase.com/organization/duocircle-llc","https://www.linkedin.com/company/duocircle","https://github.com/duocircle"],"subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]}}}
```

```json
[{"@context":"https://schema.org","@type":"BlogPosting","headline":"How Can You Identify Which SPF Include Adds the Most DNS Lookups?","description":"Learn how to identify which SPF include adds the most DNS lookups, optimize your SPF record, avoid the 10-lookup limit, and improve email deliverability.","url":"https://autospf.com/blog/identify-spf-include-with-most-dns-lookups/","datePublished":"2026-10-06T00:00:00.000Z","dateModified":"2026-10-06T00:00:00.000Z","dateCreated":"2026-10-06T00:00:00.000Z","author":{"@type":"Person","@id":"https://autospf.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://autospf.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin is the General Manager of DuoCircle, the company behind AutoSPF, DMARC Report, Phish Protection, and Mailhop. He founded DuoCircle in 2014 to solve the SPF 10-DNS-lookup problem at scale and has led the company's growth to 2,000+ customers. Brad's focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement) rather than hands-on DNS engineering.","image":"https://media.mailhop.org/autospf/images/authors/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"AutoSPF","url":"https://autospf.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com","logo":{"@type":"ImageObject","url":"https://autospf.com/images/autospf-logo.png"},"description":"Automatic SPF flattening and email authentication management. Resolve SPF lookup limits, flatten SPF records, and maintain email deliverability across all your domains.","parentOrganization":{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138883901","name":"DuoCircle LLC","url":"https://www.duocircle.com","sameAs":["https://www.wikidata.org/wiki/Q138883901","https://www.crunchbase.com/organization/duocircle-llc","https://www.linkedin.com/company/duocircle","https://github.com/duocircle"],"subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"sameAs":["https://www.wikidata.org/wiki/Q138897474","https://www.linkedin.com/company/autospf","https://x.com/autospf01","https://www.g2.com/products/autospf/reviews"],"contactPoint":{"@type":"ContactPoint","contactType":"customer support","url":"https://autospf.com/contact-us/"},"knowsAbout":["SPF Record Flattening","Sender Policy Framework","Email Authentication","DNS Management","DMARC","DKIM"]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://autospf.com/blog/identify-spf-include-with-most-dns-lookups/"},"articleSection":"advanced","keywords":"","image":{"@type":"ImageObject","url":"https://media.mailhop.org/autospf/sender-policy-framework-office-365-6321-1791287729137.jpg","caption":"Adds the Most DNS Lookups"},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}},{"@context":"https://schema.org","@type":"FAQPage","mainEntity":[{"@type":"Question","name":"Does an MX mechanism count once or multiple times?","acceptedAnswer":{"@type":"Answer","text":"*For the SPF 10-lookup limit, an `mx` mechanism counts as one DNS-querying mechanism when it is evaluated*. SPF then processes the [MX records](https://www.cloudns.net/wiki/article/12/) and checks the associated host addresses according to the RFC-defined rules and limits. Do not simply add every..."}},{"@type":"Question","name":"Do cached DNS responses reduce the lookup count?","acceptedAnswer":{"@type":"Answer","text":"No. The RFC limit applies to logical evaluation steps, not network round-trips. A warm resolver may issue fewer network queries, but your evaluator must still count each logical lookup once. AutoSPF separates logical lookups from network trips in reports."}},{"@type":"Question","name":"How should I handle PTR in counting?","acceptedAnswer":{"@type":"Answer","text":"Treat ptr as one logical mechanism that can fan out into **multiple reverse and forward** DNS queries; it is costly and discouraged. AutoSPF can flag ptr usage and estimate worst-case cost or block it in CI."}},{"@type":"Question","name":"What about CNAMEs under A or MX?","acceptedAnswer":{"@type":"Answer","text":"*Each CNAME hop is another DNS query and should be counted. AutoSPF traces and attributes these to the parent mechanism/include*."}},{"@type":"Question","name":"Can I attribute nested includes back to the top-level provider include I added?","acceptedAnswer":{"@type":"Answer","text":"Yes. Best practice is to attribute all downstream costs to the top-level include for operational decisions; AutoSPF supports both top-level attribution and split attribution views."}}]}]
```

```json
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://autospf.com/"},{"@type":"ListItem","position":2,"name":"Blog","item":"https://autospf.com/blog/"},{"@type":"ListItem","position":3,"name":"Advanced","item":"https://autospf.com/advanced/"},{"@type":"ListItem","position":4,"name":"How Can You Identify Which SPF Include Adds the Most DNS Lookups?","item":"https://autospf.com/blog/identify-spf-include-with-most-dns-lookups/"}]}
```
