All checks
Emailmediumspf-too-many-dns-lookups

SPF record exceeds the 10 DNS-lookup limit

The SPF record on `your domain` contains too many mechanisms that each cost a DNS lookup to evaluate (include, a, mx, ptr, exists, redirect), and RFC 7208 caps evaluation at 10.

Why it matters

The SPF record on `your domain` contains too many mechanisms that each cost a DNS lookup to evaluate (include, a, mx, ptr, exists, redirect), and RFC 7208 caps evaluation at 10. A receiver that hits the cap is required to treat the whole check as a permanent error — mail from your genuine senders can start failing SPF with no warning, and the failure is intermittent, since it depends on the mechanism order and each provider's own lookup count. This count is from mechanisms written directly in this record; nested lookups inside any `include:` mechanism push the real total higher still.

How ShipReady detects it

Email-authentication DNS records (DMARC / SPF). Almost every AI-built SaaS sends transactional email — password resets, magic links, receipts — through Resend, SendGrid or Postmark. Setting that up gets the mail delivered; it does not stop anyone else sending mail that claims to come from the same domain. Without a DMARC policy, a receiving server has no instruction to reject a forgery, so an attacker can send "reset your password" from the product's own domain and the message will land in the inbox looking authentic. This check is almost entirely DNS rather than HTTP — one exception is MTA-STS, whose policy is only half-published in DNS; the other half is a file fetched over HTTPS (see _check_mta_sts). Nearly everything else here is the most deterministic kind of check the scanner has: a record either exists or it does not, so there is no heuristic and no false-positive surface. The one place judgement is required is deciding WHICH domain to ask about — see _organizational_domain.

Detection is deterministic. ShipReady reports this only when it observes the condition directly, and prefers to miss a real problem over inventing one. Rule version 1.10.0.

How to fix it

This is the prompt ShipReady puts in your report — written to be pasted straight into Cursor, Claude Code, or whichever assistant built the app.

The SPF record on your domain contains multiple mechanisms that each cost one DNS lookup to evaluate (include, a, mx, ptr, exists, redirect), and RFC 7208 caps evaluation at 10 — a receiver that hits the limit treats the whole check as a permanent error, so mail from your real senders can start failing SPF intermittently with no warning. Reduce the count: replace an `include:` for a provider you no longer use, flatten a redundant include into its underlying ip4:/ip6: ranges if the provider publishes them, or consolidate multiple provider includes where one already covers another's ranges. This count is only the mechanisms written directly in your record — nested lookups inside each include: push the real total higher, so leave margin rather than trimming to exactly 10.

Frequently asked questions

What does "SPF record exceeds the 10 DNS-lookup limit" mean?
The SPF record on `your domain` contains too many mechanisms that each cost a DNS lookup to evaluate (include, a, mx, ptr, exists, redirect), and RFC 7208 caps evaluation at 10.
How serious is it?
ShipReady rates this medium. Fix soon. Meaningfully weakens a defence or degrades how the site works.
How do I fix it?
Paste the fix prompt on this page into Cursor, Claude Code or your AI editor. It is the same prompt ShipReady puts in your report.
Can I check my own site?
Yes — ShipReady scans up to ten pages of any public site for free and reports this alongside every other check. The free report lists every issue it finds and shows full evidence and a fix prompt for the critical and high-severity ones; medium and low findings are counted and unlock on Pro.

Related checks

Run this check on your site

ShipReady checks this and 193 other things across up to ten pages of your site, with an AI-ready fix for each. Free, no signup.