How much of its DNS lookup budget does your SPF record spend?
A published SPF record may use at most ten terms that cause a DNS query — include, a, mx, ptr, exists and the redirect modifier — counted through every record it includes. RFC 7208 section 4.6.4: “SPF implementations MUST limit the total number of those terms to 10 during SPF evaluation, to avoid unreasonable load on the DNS. If this limit is exceeded, the implementation MUST return ‘permerror’.”
Measured reference, updated from real published records: what each SPF include actually costs in DNS lookups — include:_netblocks.mimecast.com costs nine of your ten; the regional record costs one.
Records go over the limit quietly. Nothing warns you: your own mail keeps arriving, and the failure shows up as other people’s receivers refusing to make a judgement about you. This reader expands your record through every include and prints the whole chain with the number each level contributes.
It reads public DNS and nothing else. It sends no mail, touches no mailbox, and stores nothing you type.
Read the DMARC and SPF records themselves · The measured dataset · What else we do