Facebook Tracking Pixel
Loading...
Schedule a Conversation

DIAGNOSTIC ERROR

Multiple SPF Records & SPF PermError

RFC 7208 strictly requires exactly one SPF record per domain and limits DNS lookups to 10.

Emails currently bouncing? Jump straight to our free diagnostic tool to see if your domain is violating the 10-lookup limit, or read below to learn how to fix it.

Free Email Diagnostic Scanner

The Problem

"Multiple SPF Records" is the single most common validation failure that causes an SPF PermError. Receiving mail servers immediately drop your emails if your domain returns more than one TXT record starting with v=spf1, or if processing your record exceeds the strict 10-lookup limit imposed by RFC 7208.


RFC 7208 Section 4.5: The Multiple SPF Records Prohibition

When you set up a new service (like Google Workspace, Microsoft 365, Mailchimp, or QuickBooks), their setup guide often says "Add this TXT record to your DNS." What they really mean is "Add our specific mechanism to your existing SPF record."

Mistakenly creating a brand-new TXT record specifically for that service directly violates the official internet standard defining SPF (RFC 7208, Section 4.5). According to the RFC specification, a domain MUST NOT publish multiple records. If multiple records starting with v=spf1 exist, the evaluation stops immediately and returns a fatal "PermError" (Permanent Error). The receiving mail server does not merge them—it discards both records and rejects the email.


RFC 7208 Section 4.6.4 & Section 3.2: The 10-DNS-Lookup Limit

Even if you publish only one SPF record, you can still trigger an SPF PermError by exceeding the strict maximum of 10 recursive DNS lookups (RFC 7208 Section 4.6.4). Every time your SPF record calls an include, a, mx, ptr, or redirect mechanism, the receiving mail server must perform additional DNS queries.

Example of Lookup Accumulation:

Total Lookups = ∑(include) + ∑(a) + ∑(mx) + ∑(ptr)

Consider this common multi-provider SPF record:

v=spf1 include:_spf.google.com include:spf.protection.outlook.com include:servers.mcsv.net ~all
  • include:_spf.google.com requires 4 lookups.
  • include:spf.protection.outlook.com requires 2 lookups.
  • include:servers.mcsv.net (Mailchimp) requires 3 lookups.
Current Count = 4 + 2 + 3 = 9 lookups

If you add just one more third-party sending tool requiring 2 lookups, your total becomes 11. Since 11 > 10, this triggers a fatal SPF PermError under RFC 7208 Section 4.6.4.


RFC 7208 Section 5.5: Why the PTR Mechanism is Strictly Discouraged

Under RFC 7208 Section 5.5, using the ptr mechanism in SPF records is formally discouraged. The ptr mechanism imposes severe operational burdens on DNS root servers, slows down email processing, and is actively ignored or penalized by major receivers like Gmail and Microsoft 365. Always replace ptr mechanisms with explicit ip4: or ip6: address blocks.


Step-by-Step Merge Guide: How to Fix Multiple SPF Records

To recover deliverability, you must merge all of your separate SPF records into a single, cohesive TXT record. Follow this 5-step process:

  1. Identify all existing SPF records: Query your DNS for all TXT records starting with v=spf1.
  2. Combine mechanisms into one list: Extract every unique include:, ip4:, and a mechanism across the records.
  3. Enforce valid structure: Start with v=spf1, place all mechanisms in the middle, and finish with a single -all (hard fail) or ~all (soft fail) directive.
  4. Delete duplicate TXT records: Remove the secondary TXT records so only one SPF record exists in DNS.
  5. Validate lookup counts: Run our free validator below to ensure your total DNS query count is ≤ 10.

Example of Merged Single SPF Record:

v=spf1 ip4:192.0.2.1 include:_spf.google.com include:spf.protection.outlook.com -all

Alternative Strategy: Use a Subdomain

If your combined services exceed the 10-lookup limit, or if you simply want to isolate your email reputation, the best practice is to send marketing or transactional emails from a dedicated subdomain (for example, notify.yourdomain.com or marketing.yourdomain.com).

Because SPF limits are evaluated per domain/subdomain natively, creating a subdomain gives you a fresh 10-lookup limit and a separate TXT record for those specific services. Services like Mailchimp and SendGrid highly recommend this approach because it keeps your root domain clean and limits the blast radius if a third-party service's IP reputation is compromised.

Get Expert Help Consolidating Your DNS

Struggling to safely flatten your DNS records? One wrong move can take your entire company's email offline. Let our digital identity experts fix your SPF, DKIM, and DMARC for a flat rate of $250.

Calculate Price Call Us Email Icon Contact Us Shield Icon Free Email Scan