Forum Discussion

AP15's avatar
Icon for Altostratus rankAltostratus
Jul 11, 2023

SPF TXT lookup limit RFC 7208 4.6.4

Can someone please confirm best way to include more DNS lookup within SPF record. How does F5 implementation work for 10+ lookup records? 
  • Leslie_Hubertus's avatar
    Jul 17, 2023

    Hi AP15  - FYI - I've floated this post to the top of the forum for now, to give your post more visibility and a higher chance of getting an answer from the community. 

  • JRahm's avatar
    Jul 25, 2023

    Hi AP15 ... max 10 is the standard, you'll break SPF and bad things will happen, so you don't want to do that. However, there are ways to work around the issue. Check out autoSPF and analyze any domain and it will give you pointers. For example, the domain has a query count of 5/10, which they offer a solution to reduce to 2/10 by sharding the load like so:

    v=spf1 ip4: ip4: ip4: ip4: ip4: ip4: ip4: ip4: ip4: ip4: ip4: ip4: ip4: ip4: ip4: ip4: ip4: ip4: ip4: ip4: ip4: -all spf:
    v=spf1 ip4: ip4: ip4: ip4: ip4: ip4: ip4: ip4: ip4: ip4: ip4: ip4: ip4: ip4: ip4: ip4: ip6:2a01:111:f400::/48 ip6:2a01:111:f403::/49 ip6:2a01:111:f403:8000::/50 -all spf:
    v=spf1 ip6:2a01:111:f403:c000::/51 ip6:2a01:111:f403:f000::/52 exists:%{i} exists:%{i} -all