Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

SPF’s “10 DNS lookups” limit is a budget for specific terms evaluated across the full SPF policy chain—not a count of visible include: strings or every DNS packet. My checker first reported 8 of 10 for GitHub, then reported 10 after I corrected how it counted nested policy terms. That GitHub figure is my checker’s finding, not an independently verified snapshot of GitHub’s live DNS policy; SPF records can change.

Why a top-level SPF record can undercount

An SPF record can refer to another domain’s policy with include: or hand evaluation off with redirect=. Those references make the evaluated policy larger than the single record a checker may display. SPF’s limit applies across the evaluation, including the lookup-causing terms encountered in referenced policies. Counting only the top-level record—or counting only its visible include: strings—can therefore produce a misleading total.

RFC 7208 §4.6.4 requires SPF implementations to limit the total number of these terms to 10 during evaluation. The same rule applies as nested policies are evaluated; it is not a separate allowance for each referenced domain. The RFC describes the limit as protection against unreasonable DNS load. RFC 7208 §4.6.4

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Which SPF terms count toward the ten-term budget?

The count is based on the SPF mechanism or modifier being evaluated, not simply on whether a DNS packet happened to be sent. RFC 7208 identifies these as lookup-causing terms:

  • include
  • a
  • mx
  • ptr
  • exists
  • redirect

They count when reached during SPF evaluation, including through referenced policies. Some terms that appear in a record do not consume this ten-term budget: all, ip4, and ip6 do not cause DNS queries during evaluation. The exp modifier is also excluded from this evaluation-time limit because its explanation lookup occurs after the SPF evaluation. RFC 7208 §4.6.4

What the GitHub checker discrepancy means

In my checker, the initial result was 8 of 10 for github.com; after I corrected the implementation, it counted 10. The lesson is about the counting method: a checker needs to follow nested SPF evaluation and account for every applicable lookup-causing term, rather than treating top-level references as the total.

This should not be read as a permanent property of GitHub’s SPF setup. The reported result describes my checker’s analysis; the live DNS policy was not independently retrieved and evaluated for this explanation, and published SPF records can change. To assess a result from any checker, look for whether it follows nested include and redirect paths and reports the terms counted—not merely a top-level token count.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What happens when SPF exceeds 10?

RFC 7208 says that if an SPF evaluation exceeds the ten-term limit, the implementation must return permerror. The RFC defines this as a case where the domain’s published records could not be correctly interpreted, and says it requires DNS operator intervention. It is not the same as a temporary DNS failure: the limit is a policy-evaluation error, not a transient network condition. RFC 7208 §§2.6.7, 4.6.4

Other SPF DNS limits are separate

The ten-term budget is not the only DNS-related constraint in RFC 7208, but other limits do not add to it. For each mx mechanism, the RFC separately limits the address records queried for each MX record. It also recommends limiting “void lookups” to two. These rules address different parts of evaluation; they do not raise the global ten-term limit. RFC 7208 §4.6.4

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Why accurate counting matters beyond one checker

The limit can affect real domains, not just synthetic examples. A USENIX Security 2024 study reported that 3,584,014 domains—6.5% of the domains in its study—required more than 10 DNS lookups. The paper’s dataset snapshot was dated March 27, 2023, so this is a historical study result, not an estimate of prevalence on the 2026 internet. USENIX Security 2024 paper

Cloudflare’s documentation likewise describes SPF as allowing ten relevant lookups per check. Cloudflare: DNS lookup limit

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.