Expand a domain's SPF record in full — every include, what each term costs, and the two limits that break a record without telling you.
The ten-lookup limit is famous enough that most checkers count it. The second one is not: a lookup that returns nothing is a void lookup, and a record is allowed only two before a receiving server should return the same permanent error as going over ten.
So a record can sit comfortably at six lookups, pass every tool that counts to ten, and still fail — because three of the vendors in it shut down and nobody removed the includes. This page counts both, and marks every term that resolves to nothing.
An SPF record may cost at most ten DNS lookups to evaluate. Every include, a, mx, ptr and exists costs one, and so does a redirect — counted recursively, so the lookups inside a record you include count against your ten as well. Go over and receiving servers return a permanent error, and most then treat your domain as having no SPF at all.
The most likely answer is void lookups, which is the limit nobody checks. A lookup that returns nothing — a vendor who has shut down, a name with a typo in it — is a void lookup, and a record is allowed only two of them before a receiver should return the same permanent error. A record can sit at six lookups, look fine in every tool that counts to ten, and fail on this instead.
Because the limit counts through includes, and most of yours belong to other companies. When a provider you include adds an address range or another include to their own record, your total goes up. Nothing tells you, there is no error anywhere you would see it, and the first symptom is mail being filed as spam.
Remove sending services you no longer use, which is usually most of the problem. Replace an include with the ip4 and ip6 ranges it resolves to if the provider publishes stable addresses, since literal ranges cost nothing. Drop any ptr term. And check the tree on this page for the same name reached twice by different routes — each occurrence is charged separately.
Every change published to our nameservers in seconds, with a full history of what changed and a recycle bin for the days it goes wrong. Every zone is DDoS-protected, on every plan including the free one.