SPF report

sk-c.in

4 / 10 DNS lookups

Flatten sk-c.in

Free for one domain. No credit card.

SPF Health

95 / 100
Risk Low

4 / 10 DNS lookups

  • 95–100 Healthy
  • 80–94 Good
  • 60–79 Needs attention
  • 40–59 High risk
  • 0–39 Critical

Include depth: 3

Estimated with SPF Manager

100 / 100 · 3 / 10 lookups

This record uses 4 of 10 DNS lookups

SPF Lookup Limit: The 10 DNS Lookup Rule

RFC 7208 limits SPF evaluation to ten DNS lookups, and exceeding that limit causes a PermError that breaks authentication.

Read article

Microsoft 365 contributes 2 lookups. secureserver.net contributes 1 lookup. spf-0.secureserver.net contributes 1 lookup. Total: 4 / 10 lookups.

Detected sources

Microsoft 365 · 2 lookups secureserver.net · 1 lookup spf-0.secureserver.net · 1 lookup

What we found

Nothing to report. This record parses cleanly, stays inside the DNS lookup limit, and every include it points at answers.

How the 4 lookups are counted

RFC 7208 counts one DNS lookup for each include, redirect, a, mx, ptr, and exists mechanism evaluated — including nested chains.

4 / 10 used

Microsoft 365 · 2 secureserver.net · 1 spf-0.secureserver.net · 1
  1. 1
    include secureserver.net

    Counted toward secureserver.net

  2. 2
    include spf-0.secureserver.net Nested

    Counted toward spf-0.secureserver.net · depth 2

  3. 3
    include spf.protection.outlook.com Nested

    Counted toward Microsoft 365 · depth 3

  4. 4
    include spf.protection.outlook.com

    Counted toward Microsoft 365

Each row is one DNS lookup consumed while evaluating your SPF record. The segments above sum to 4.

What if you changed something

Turn a sender off to see what removing it would free up, or add one to see how close it takes you to the limit. Nothing here changes your DNS — it is arithmetic on the numbers above.

Add more sender(s), each costing

Lookups in that scenario

/

Starting point: 4 of 10 lookups as published today.

How your SPF chain becomes one include

See what changes when sk-c.in moves to one managed include.

Current situation

Health score
95 / 100
Lookup count
4 / 10
Detected providers
Microsoft 365 secureserver.net spf-0.secureserver.net
Risk
LOW

After SPF Manager

Health score
100 / 100
Lookup count
3 / 10
Room to grow
7 lookups spare
Providers
Automatically managed
Risk
NONE
Score potential 95 → 100

Watch the chain collapse

Watch nested provider includes collapse into a single managed include.

Before After

Your DNS today

TXT @ sk-c.in

v=spf1 include:… +3 includes

4 / 10 lookups

Microsoft 365

Nested

include:spf.protection.outlook.com

2 lookups

secureserver.net

Unidentified

include:secureserver.net

1 lookup

spf-0.secureserver.net

Nested Unidentified

include:spf-0.secureserver.net

1 lookup

With SPF Manager

TXT @ sk-c.in

v=spf1 include:sk-c.in.flat-spf.com -all

3 / 10 lookups

SPF

Managed include

sk-c.in.flat-spf.com

Resolves 3 providers automatically

Validated · 3 / 10 lookups
Paused — compare your current SPF chain with one managed include side by side. Each provider include consumes DNS lookups toward the 10-lookup limit. Flattening provider includes into one managed record… Your public SPF stays simple — SPF Manager maintains the rest.

What changes if you let us manage it

One include, whatever you add

Your record becomes a single include that we host. Adding another provider later changes what resolves behind it, not what you publish, so your own record stops growing toward the 10-lookup limit.

Provider changes are our problem

When a provider quietly starts sending from new addresses — or starts costing more lookups than it used to — we see it and republish. You never find out from a bounce.

Always current, never touched

You publish one TXT record once. From then on the addresses behind it stay correct without you editing DNS again.

Flatten sk-c.in

Free for one domain. No credit card.

Specific actions for this domain

  • Replace nested includes

    Include depth is 3. Nested provider chains increase permerror risk and make troubleshooting harder.

  • Switch to a managed include

    Publish one managed include in DNS and let SPF Manager resolve provider includes behind it.

All SPF includes

Expand each source to see include records, lookup contribution, nesting depth, and guidance.

  • include:spf.protection.outlook.com
    Nested depth 3 2 lookups

Recommendation: keep authorized, but monitor for nested include changes.

Managed automatically with SPF Manager

  • include:secureserver.net
    depth 1 1 lookup

Recommendation: keep authorized, but monitor for nested include changes.

Managed automatically with SPF Manager

  • include:spf-0.secureserver.net
    Nested depth 2 1 lookup

Recommendation: keep authorized, but monitor for nested include changes.

Managed automatically with SPF Manager

Share this report

Send it to whoever manages your DNS before anything changes.

Analyzed 0 seconds ago.