Email deliverability

SPF flattener

Get an SPF record under the 10-lookup limit by replacing includes with the IP addresses they publish today. Only exact replacements, split into records that fit.

The domain whose SPF record you want to flatten. An email address or link works too.

Questions

When should I flatten, and when not?

Flatten only when the record needs more than 10 DNS lookups and you can’t get under the limit another way. First remove includes for services you no longer use, and move bulk or marketing mail to a subdomain (such as news.example.com) with its own SPF record. Those fixes don’t go stale. If the record already uses 8 or fewer lookups, don’t flatten: you gain nothing and take on upkeep.

Why is there a 10-lookup limit?

Each include, a, mx, ptr, exists and redirect makes the receiving server query DNS while your message waits. RFC 7208 §4.6.4 caps them at 10 per check, nested includes counted, so one record can’t be used to flood DNS servers or stall mail. A check that needs an 11th lookup ends in permerror, which DMARC treats as an SPF fail. ip4 and ip6 cost nothing, which is why flattening works.

Which includes can’t be flattened?

An include matches only when the included record returns pass (RFC 7208 §5.2), so only the addresses it passes can be copied: ip4 and ip6 terms with a pass qualifier, and a and mx resolved to their addresses. An include is kept when it uses exists, ptr or macros such as %{i}, which are worked out per message, when a -, ~ or ? term comes before a pass term it could overlap, or when part of it is broken (a missing record or a failed lookup). The table says why for each one.

What breaks when a provider changes its IP addresses?

Mail from the new addresses fails SPF, because your copy still lists the old ones. If the message is DKIM-signed with your domain, DMARC can still pass on DKIM; if not, receivers may reject or junk it. Nothing warns you: the first sign is usually bounces or lower inbox placement. Keep your original record so you can roll back in minutes.

How often should I re-check?

At least once a week, and whenever a provider tells you about new addresses. Open this page with your domain (the link keeps it), compare the records with what you published, and publish again if they differ. Providers change their ranges without asking you first, so a flattened record needs a calendar reminder.

How do the _spf1 and _spf2 records work?

A TXT record should stay under 450 characters so the answer fits in one DNS packet. When the networks don’t fit, they go into extra records named _spf1.example.com, _spf2.example.com and so on, and your main record includes them. Each holds only ip4 and ip6 terms and no all, so including it matches exactly when the sender is in one of its networks. Each costs one lookup. Publish them first, then replace the main record. Most DNS dashboards want only the part before your domain, such as _spf1.

Is anything sent to tanase.ai?

No. The page works in your browser: DNS questions go from your browser to Cloudflare’s public DNS-over-HTTPS resolver, or to Google’s if Cloudflare doesn’t answer, and the records are built on the page. The domain isn’t sent to tanase.ai unless it is in a link you open (a shared result, for example), which appears in the request logs described on the privacy page.

esc