DIAGNOSTIC ERROR
Multiple SPF Records & SPF PermError
RFC 7208 strictly requires exactly one SPF record per domain and limits DNS lookups to 10.
Emails currently bouncing? Jump straight to our free diagnostic tool to see if your domain is violating the 10-lookup limit, or read below to learn how to fix it.
Free Email Diagnostic ScannerThe Problem
"Multiple SPF Records" is the single most common validation failure that causes an SPF PermError. Receiving mail servers immediately drop your emails if your domain returns more than one TXT record starting with v=spf1, or if processing your record exceeds the strict 10-lookup limit imposed by RFC 7208.
RFC 7208 Section 4.5: The Multiple SPF Records Prohibition
When you set up a new service (like Google Workspace, Microsoft 365, Mailchimp, or QuickBooks), their setup guide often says "Add this TXT record to your DNS." What they really mean is "Add our specific mechanism to your existing SPF record."
Mistakenly creating a brand-new TXT record specifically for that service directly violates the official internet standard defining SPF (RFC 7208, Section 4.5). According to the RFC specification, a domain MUST NOT publish multiple records. If multiple records starting with v=spf1 exist, the evaluation stops immediately and returns a fatal "PermError" (Permanent Error). The receiving mail server does not merge them—it discards both records and rejects the email.
550 5.7.1 SPF PermError, while others route all corporate correspondence to spam.
RFC 7208 Section 4.6.4 & Section 3.2: The 10-DNS-Lookup Limit
Even if you publish only one SPF record, you can still trigger an SPF PermError by exceeding the strict maximum of 10 recursive DNS lookups (RFC 7208 Section 4.6.4). Every time your SPF record calls an include, a, mx, ptr, or redirect mechanism, the receiving mail server must perform additional DNS queries.
Example of Lookup Accumulation:
Consider this common multi-provider SPF record:
include:_spf.google.comrequires 4 lookups.include:spf.protection.outlook.comrequires 2 lookups.include:servers.mcsv.net(Mailchimp) requires 3 lookups.
If you add just one more third-party sending tool requiring 2 lookups, your total becomes 11. Since 11 > 10, this triggers a fatal SPF PermError under RFC 7208 Section 4.6.4.
RFC 7208 Section 5.5: Why the PTR Mechanism is Strictly Discouraged
Under RFC 7208 Section 5.5, using the ptr mechanism in SPF records is formally discouraged. The ptr mechanism imposes severe operational burdens on DNS root servers, slows down email processing, and is actively ignored or penalized by major receivers like Gmail and Microsoft 365. Always replace ptr mechanisms with explicit ip4: or ip6: address blocks.
Step-by-Step Merge Guide: How to Fix Multiple SPF Records
To recover deliverability, you must merge all of your separate SPF records into a single, cohesive TXT record. Follow this 5-step process:
- Identify all existing SPF records: Query your DNS for all TXT records starting with
v=spf1. - Combine mechanisms into one list: Extract every unique
include:,ip4:, andamechanism across the records. - Enforce valid structure: Start with
v=spf1, place all mechanisms in the middle, and finish with a single-all(hard fail) or~all(soft fail) directive. - Delete duplicate TXT records: Remove the secondary TXT records so only one SPF record exists in DNS.
- Validate lookup counts: Run our free validator below to ensure your total DNS query count is ≤ 10.
Example of Merged Single SPF Record:
Alternative Strategy: Use a Subdomain
If your combined services exceed the 10-lookup limit, or if you simply want to isolate your email reputation, the best practice is to send marketing or transactional emails from a dedicated subdomain (for example, notify.yourdomain.com or marketing.yourdomain.com).
Because SPF limits are evaluated per domain/subdomain natively, creating a subdomain gives you a fresh 10-lookup limit and a separate TXT record for those specific services. Services like Mailchimp and SendGrid highly recommend this approach because it keeps your root domain clean and limits the blast radius if a third-party service's IP reputation is compromised.
Related Email Authentication Issues
Get Expert Help Consolidating Your DNS
Struggling to safely flatten your DNS records? One wrong move can take your entire company's email offline. Let our digital identity experts fix your SPF, DKIM, and DMARC for a flat rate of $250.