Audit your SPF record DNS lookup count and identify which includes can be flattened.
The SPF specification limits records to 10 DNS lookups. Exceeding this causes PermError — effectively breaking SPF for your domain.
RFC 7208 limits SPF records to 10 DNS-resolving mechanisms. Exceeding this returns PermError, which many receivers treat as SPF failure — breaking email authentication for your entire domain.
Each include:, a:, mx:, and redirect= costs one lookup. Nested includes in third-party records count against your limit too.