Mail Sorcery

breaking spf - forgotten records

How Can You Break SPF? A Tour Of Common Mistakes

Before You Continue

If SPF itself still feels a bit fuzzy, start here:

./demystifying-spf.md

Then continue with this guide.

SPF records rarely break in one dramatic moment. They break slowly, one small addition at a time, over years, usually without documentation, and usually without anyone noticing until deliverability quietly drops off a cliff.

Here’s how it usually happens.

The Junk Drawer Effect

Every company has a junk drawer. Batteries, random cables, a key that doesn’t open anything anymore. SPF records tend to become the DNS equivalent.

A typical investigation looks something like this:

Investigation results:

  • Microsoft 365
  • 2 Marketing Platforms
  • A deprecated CRM platform
  • An ERP system
  • An unknown scanner

Nobody knew what the scanner did. Nobody wanted to unplug it. It had therefore become business critical.

Every one of those systems got added to SPF at some point, usually in a hurry, usually by someone who has since left the company. Nobody ever comes back to remove entries. Removing things from DNS feels risky, so people just keep adding.

The Usual Suspects

Too Many External Senders

Marketing platforms, transactional mail services, CRM systems, ticketing platforms, ERP systems, invoicing tools. Every SaaS product added to the business wants to send mail “as you” for better deliverability, so every one of them asks for an SPF include. Nobody ever says no.

Forgotten Systems

The CRM platform you replaced three years ago is often still in your SPF record, quietly authorized to send mail nobody sends anymore. It’s not doing any harm sitting there, except that it’s using up one of your precious DNS lookups. We’ll get into why that matters in the next guide.

Scanners And Printers

Every office has at least one multifunction printer or scanner configured to email scanned documents directly using SMTP. Someone, at some point, added its IP address to SPF. That printer has since been replaced twice, but the entry lives on forever, like digital wallpaper.

Multiple SPF Records

DNS allows you to create more than one TXT record starting with v=spf1. Receiving mail servers do not allow this. If a domain has two SPF records, most receivers treat this as invalid, and SPF checks may fail entirely. This usually happens when two different teams or vendors each set up their own SPF record without checking what was already there.

Syntax Mistakes

SPF syntax is strict and unforgiving. Missing colons, wrong mechanism order, or a stray space can silently break the entire record. Unlike a typo in a Word document, nobody proofreads DNS.

The Dreaded +all

Somewhere out there, SPF records still exist ending in +all instead of -all or ~all. This mechanism means “allow absolutely anyone to send mail as this domain,” which defeats the entire purpose of SPF. If you find this in a client’s DNS, take a breath before you say anything out loud.

Two Big Causes Worth Their Own Articles

Two specific failure modes are common enough, and confusing enough, that they deserve dedicated guides:

  • The SPF DNS lookup limit. SPF allows a maximum of 10 DNS lookups. Exceed it, and the entire record can fail, even if it looks perfectly fine at a glance. Covered in ./spf-dns-lookup-limit.md.
  • SPF breaking during email forwarding. Even a clean, correct SPF record can fail once a message gets forwarded through another system. Covered in ./spf-breaking-during-forwarding.md.

Continue Reading

Sponsored