SPF Flattening Tool

Fix the 10-Lookup Limit

Our free SPF flattening tool resolves every include in your SPF record into a flat list of IP addresses, so you stay under the 10 DNS lookup limit.

spf flatteningspf flattening

How to Use the SPF Flattening Tool

Using our SPF flattening tool requires only a few clicks and gives you immediate visibility into your email authentication infrastructure. Instead of guessing how many lookups your providers consume behind the scenes, you can diagnose and fix the problem in minutes.

1
Paste your domain or SPF record

Start by entering your domain name or pasting your existing raw SPF record into the tool. The system will automatically query public DNS to pull the active record.

2
Review your lookup count

The tool parses your record and displays exactly how many DNS lookups you are currently using. It breaks down the count by provider to show you exactly which includes are consuming your limits.

3
Generate the flattened record

With a single click, the tool traces every nested include, extracts the underlying IP addresses, and condenses them into a clean, flat list.

4
Publish or automate

You can copy the newly flattened record and manually update your DNS registrar or switch to automatic updates. Our platform will monitor your vendors and refresh the IPs automatically.

See Your SPF Record Flattened Before Touching Your DNS

Not sure what your flattened record will look like? Add your email senders, watch the DNS lookup count build in real time, and preview the exact flattened output, before making any changes to your live DNS.

What Is SPF Flattening?

SPF flattening is the process of converting a complex SPF record that contains multiple nested mechanisms like include:, a, mx, or redirect= into a simplified version that lists the resolved IP addresses directly. Instead of telling receiving mail servers to recursively look up which IPs each of your email vendors uses, a flattened record pre-resolves all of that data and writes the answer straight into your DNS.

SPF Record Comparison
BEFORE FLATTENING
AFTER FLATTENING
SPF Configuration

13 DNS lookups, over limit

v=spf1 include:u538675.wl176.sendgrid.net include:_spf.google.com include:spf.protection.outlook.com include:zoho.com include:amazonses.com include:spf.sendinblue.com ~all
SPF Configuration

1 DNS lookup, always within limit

v=spf1 include:kfho42w5d9.powerspf.com ~all

Using an SPF flattener allows organizations with many third-party email senders to consolidate their records. Without SPF record flattening, you risk failing authentication checks due to excessive nested lookups. A good SPF flattening service automates this process to keep your domain secure and compliant with authentication standards.

Learn more

How the 10 DNS Lookup Limit Works

Every time a receiving mail server evaluates your SPF record, it follows each include, a, or mx mechanism to find the authorized IPs. Under RFC 7208 (the formal SPF specification), this chain of resolution is capped at 10 DNS lookups. Exceed that cap, and SPF returns a PermError (permanent error), which typically causes your legitimate emails to fail authentication and land in spam or get rejected outright.

What Happens When You Exceed It (PermError)

When your record needs more than 10 lookups to resolve fully, mail servers stop evaluating at the 10th lookup, so any services listed from that point on simply go unchecked. SPF returns PermError, and depending on your DMARC policy, emails from those unchecked services may be unavailable or rejected. The failure is usually silent: you don't get a bounce but your emails will just start dropping.

Service
SPF mechanism
Lookups
Microsoft 365
include:spf.protection.outlook.com
1 (+3 nested)
Google Workspace
include:_spf.google.com
1 (+3 nested)
Mailchimp / Mandrill
include:spf.mandrillapp.com
1 (+1 nested)
Salesforce
include:_spf.salesforce.com
1 (+1 nested)
SendGrid
include:sendgrid.net
1 (+1 nested)
Zendesk
include:mail.zendesk.com
1
Total
~11 — over the limit ×

Do You Actually Need to Flatten Your SPF Record?

Before flattening your SPF record, determine whether you actually need it. The SPF 10 DNS lookup limit is often exceeded because of outdated or unnecessary entries rather than a genuine need for flattening.

Start with an SPF audit:

Review your current SPF record and identify all include: statements.

Remove entries for marketing platforms, CRM tools, and third-party vendors you no longer use.

Check whether this cleanup brings your record below the 10-lookup limit.

If you still exceed the limit after a thorough audit, consider SPF flattening or a hosted SPF solution.

Why hosted SPF is often the better choice:

Manual flattening replaces include: statements with static IP addresses, which can become outdated when vendors change their infrastructure.

Static records require ongoing monitoring and maintenance to remain accurate.

Hosted SPF dynamically manages your SPF record and lookup requirements at the server level.

This makes hosted SPF a more scalable option for organizations that rely on multiple cloud services and third-party senders.

The Core Problem with Static SPF Flattening

Flattening resolves all those include: mechanisms into their underlying IP addresses and writes them directly into your record. In theory, it eliminates the nested lookups entirely. In practice, a statically flattened record has a predictable lifespan: the moment any of your email vendors changes their IPs, your flattened record is wrong.

Record length limits

DNS TXT records have practical size limits (255 bytes per string). A fully expanded record with many IP ranges can exceed them, causing its own validation failures.

Ongoing maintenance burden

Every time you add a new email service, you re-flatten. Every time you remove one, you re-flatten. This becomes unsustainable as infrastructure grows.

Silent IP changes

No notification mechanism exists in the SPF standard. When a vendor moves IPs, you only find out when deliverability has already dropped.

How Our Automatic SPF Flattening Works

PowerDMARC's SPF flattening tool is part of the PowerSPF hosted SPF service, and handles the full process automatically, keeping your record current as your email infrastructure changes.

1
Add your domain

Sign up and add your domain. PowerDMARC auto-detects your current SPF record instantly with no manual input needed.

2
Analyze your lookups

See exactly how many DNS lookups your record uses, which services contribute the most, and whether you're at risk of PermError.

3
Flatten with one click

All include mechanisms resolve to their current IPs and compress into a single optimized include. Your count drops to 1.

4
Deploy and stay updated

Publish the new record. PowerDMARC monitors your vendors and auto-reflattens when IPs change, so it never goes stale.

Manual Flattening

Operational bottlenecks and hidden friction built on manual tracking.

Lookup limits exceeded frequently

Adding third-party services manually quickly pushes your DNS past the 10-lookup limit, breaking email delivery without warning.

Silent SPF failures

When vendors update their underlying IP addresses, your static manual record falls out of date silently until you notice broken delivery.

Unbounded character growth

Manually expanding sub-records causes strings to balloon rapidly, easily exceeding the strict 255-character limits for individual DNS strings.

Prone to human error

Typing typos, formatting syntax incorrectly, or miscopying long blocks of IP ranges introduces critical security and deliverability failures.

Hard to maintain and monitor

Requires continuous manual audits, spreadsheet monitoring, and developer time just to keep tracking standard business applications.

VS
PowerDMARC's Dynamic SPF Flattening

Automated, efficient security infrastructure inside your native environment.

Stays within limits automatically

Advanced dynamic mapping automatically condenses numerous lookups safely below the 10-lookup protocol max threshold limit.

Auto-reflattens when IPs change

Background automated checking scripts detect system vendor changes instantly, auto-refreshing network updates seamlessly inside minutes.

Compressed to the minimum size

Intelligent algorithmic text block wrapping strips redundant syntax spaces, compressing records to minimize character footpaths.

Fully automated, no manual edits

Eliminates risky custom manual structural operations, leaving software rules to systematically oversee your platform configurations error-free.

Configured once, active forever

Deploy one permanent static engine configuration handle and protect long-term digital domain authentication parameters continuously.

SPF Flattening Risks and Best Practices

SPF flattening is a legitimate technique, but it carries risks worth understanding before you rely on it, especially if you plan to maintain the record manually.

Risks to know before you start

IP address changes — Major providers regularly change outbound IP ranges; when they do, mail from the new IPs fails SPF immediately, and you only know when deliverability drops.

Record bloat & DNS limits — A flattened record for an org with many services can expand to hundreds of IP entries, pushing past practical size limits, causing Permerror.

Maintenance burden — A manual record isn't a one-time fix. Add a service, remove one, or have a vendor update infrastructure, and you re-flatten and re-publish.

Best practices

Authorize only active, legitimate senders — Before flattening, audit your record and remove includes for services you no longer use. Every unnecessary entry adds to your lookup count and attack surface.

Monitor SPF pass/fail rates in DMARC reports — Aggregate reports show exactly which sources pass and fail. Unexplained failures after flattening usually point to a stale IP range.

Use SPF alongside DKIM and DMARC — SPF alone doesn't stop spoofing. Proper authentication needs all three: SPF and DKIM for alignment, DMARC to define what happens when they fail.

Re-validate after any infrastructure change — Whenever you add or remove an email service, check your record with an SPF checker before assuming it's still valid.

For advanced use cases: SPF Macros

For complex setups with multiple sending domains, high-volume infrastructure, and frequently changing vendor IPs - SPF Macros use dynamic variables that resolve at evaluation time, bypassing the 10-lookup limit without ever updating your DNS. PowerSPF supports both flattening and Macros: automated flattening suits most organizations; Macros are the more durable enterprise choice.

SPF Flattening Approaches Compared

Managing the DNS lookup limit can be handled in a few different ways. Here is a comparison of the four main approaches available today.

Approach
Who Maintains It?
When a Vendor Changes IPs
Lookup-Limit Safety
Record-Length Risk
Effort at Scale
Manual editing
You
Fails until you notice and manually update DNS.
High risk
High risk
Unsustainable
Static flattening tools
You (via tool)
Fails until you generate and publish a new record.
Safe
High risk
Tedious
Hosted (Dynamic) SPF
The service provider
Updates automatically in the background.
Safe
Safe
Effortless
SPF Macros
The service provider
Resolves dynamically at the time of evaluation.
Safe
Safe
Effortless

What Makes a Good SPF Flattening Tool?

A good SPF flattening tool should simplify SPF management while keeping your records accurate and reliable. Look for these key features:

Automatic updates

Does it update IP addresses when vendors change their infrastructure? This prevents outdated records and repeated manual updates.

Record length alerts

Does it warn you before your SPF record exceeds 512 bytes? Early warnings help prevent oversized DNS records and configuration issues.

Lookup visibility

Does it show which include: statements are consuming your SPF lookups? This makes it easier to identify unnecessary or high-usage entries.

Multi-domain support

Can you manage SPF records for multiple domains from one dashboard? Centralized management is useful for organizations with larger domain portfolios.

Free testing

Is there a free tier or trial you can use to test the tool? This lets you validate the solution against your actual SPF configuration.

DMARC integration

Does it integrate with DMARC reporting and deliverability data? This helps you measure the impact of SPF changes on email authentication.

Why choose PowerDMARC's SPF Flattening Tool?

Our SPF flattening tool turns a complex, manual process into a simpler, automated workflow.

Stay within the lookup limit: Convert complex SPF configurations into a single optimized include.

Automatic updates: Monitor vendor IP changes and keep your SPF record current.

Less maintenance: Get the benefits of SPF flattening without managing static IP lists manually.

Centralized visibility: Manage SPF alongside DMARC reporting and other email security tools.

Trusted by Thousands Worldwide

Jennifer Heisel

Jennifer Heisel

Systems Administrator

★★★★★

"PowerDMARC eliminates the SPF lookup limit on our domains with the hosted SPF; we only need to publish 1 SPF record to our DNS."

David Spigelman

David Spigelman

President

★★★★★

"PowerDMARC helps a lot with SPF errors, in particular, by making it easy to do "SPF Folding," which is often needed for customers who need more SPF includes than are otherwise technically allowed."

Dylan Bouterse

Dylan Bouterse

Technology Security Consultant

★★★★★

"With SPF flattening, we were able to easily expand the SPF includes to inspect the specifics of the record."

Frequently Asked Questions

What happens if my SPF record exceeds 10 lookups?
Mailbox providers have a hard time checking your SPF after the 10th lookup, so if your SPF record exceeds the limit, it usually ends with a PermError, and your legitimate emails may start getting rejected or sent to spam.
Does SPF flattening increase security?
Flattening doesn't make SPF more secure; it just helps you stay within the 10-lookup limit, enhancing the accuracy of your SPF setup. Real protection still comes from SPF + DKIM + DMARC working together.
Should I flatten records provided by Google/Microsoft?
Major email providers like Google and Microsoft update their IPs often, so a manually flattened record can go stale quickly unless you keep refreshing it. A dynamic solution like PowerDMARC resolves this issue.
How do I know when to re-flatten?
With manual flattening, any time you add or remove a mail service, or when your provider updates their IP ranges, is a good time to re-flatten your record. If you see sudden SPF failures in reports, that's another sign it's time. With our SPF flattening tool, this is automatic and hassle-free.
Is flattening still recommended in 2026?
Traditional Flattening is still useful in certain cases, but not the long-term answer. With vendors changing IPs more frequently and automation becoming the norm, dynamic SPF solutions like PowerSPF are quickly becoming the more reliable approach.
What is the difference between SPF flattening and SPF macros?
SPF flattening resolves all your include: mechanisms into direct IP addresses and writes them into your record. It reduces lookups but produces a static snapshot that needs updating whenever vendor IPs change. SPF macros use dynamic variables that resolve at evaluation time, so the record never needs updating, even when vendor infrastructure changes. Macros are technically superior but require a hosted SPF service to implement correctly. For most organizations, automated flattening is sufficient; for enterprise environments with complex multi-domain setups, macros are the more durable long-term solution.
Can I have two SPF records on the same domain?
No. RFC 7208 explicitly prohibits multiple SPF records on the same domain. If a receiving server finds more than one SPF TXT record, it returns a PermError, and both records are ignored. You must have exactly one SPF record properly configured and within the 10-lookup limit.
Is there a free SPF flattening tool?
Yes, there are free tools available that will parse your current record and generate a statically flattened list of IP addresses. However, a free static tool requires you to manually monitor your vendors for IP changes and update your DNS records yourself whenever those shifts occur.
What's the difference between an SPF flattener and hosted SPF?
A basic SPF flattener provides a one-time conversion of your nested includes into a static list of IP addresses. You publish it and maintain it manually. Hosted SPF, also known as automated SPF management, dynamically hosts your record on the provider's servers. The service tracks vendor IP changes and updates your configuration in real time.
How often do I need to re-flatten my SPF record?
If you use a static flattening tool, you must re-flatten your record every single time you add a new email service, remove an old one, or whenever an existing vendor updates their backend IP ranges. This could mean re-flattening several times a year to avoid unexpected email delivery failures.

Ready to Fix Your SPF Record?

SPF flattening doesn’t have to be a recurring problem. Our tool makes it effortless!

  • Instantly fix SPF PermError
  • Auto-updates when vendor IPs change
  • One include, maintained forever
  • Integrated with DMARC monitoring
  • No technical expertise required
  • Free for 15 days, no credit card