When and How to Flatten Your SPF Record
June 28, 2026 · 6 min read
RFC 7208 caps SPF at 10 DNS-lookup mechanisms. Every include, a, mx, ptr and exists counts. Large organizations chaining several providers routinely exceed this and trigger a permerror.
Flattening replaces include mechanisms with the underlying IP ranges, collapsing many lookups into a handful of ip4/ip6 entries. This solves the limit — but those IPs now change without your provider updating them for you.
If you flatten, automate it: re-resolve your providers' records on a schedule and regenerate your SPF so you don't silently drift out of sync.