
You send an email to a client. It’s professional, relevant, and expected. But it never arrives in their inbox – it goes straight to spam, or worse, gets blocked entirely. You only find out when they mention they never received it.
This happens more often than you’d think, and the culprit is usually something called an SPF record. It’s one of those invisible bits of email infrastructure that nobody thinks about until it stops working.
Curious how your own domain scores? Run a free scan below and see your email authentication grade in seconds.
Want to receive a full detailed report?
The frustrating part? Even if you’ve got an SPF record set up, it might not be doing what you think it’s doing. Let’s talk about what SPF actually is, why it matters to your business, and why “just having one” isn’t always enough.
What Is SPF (In Plain English)?
SPF stands for Sender Policy Framework, but that doesn’t tell you much. Here’s what it actually does:
Think of SPF as a guest list for your email. When you send an email from your domain (say, yourname@yourbusiness.com), the receiving mail server checks your SPF record to see if the server sending that email is on the approved list. If it is, the email passes. If it isn’t, the email gets flagged as potentially suspicious.
It’s essentially your way of saying “these mail servers – and only these servers – are authorized to send email on behalf of my domain.”
Without SPF, anyone could send emails that appear to come from your domain. That’s how email spoofing works, and it’s why SPF exists in the first place.
Why Your Business Should Care About SPF
Email deliverability isn’t just an IT concern – it’s a business continuity issue. If your emails aren’t reaching clients, prospects, or suppliers, you’re losing opportunities and damaging relationships without even knowing it.
Here’s what happens when your SPF record is missing, misconfigured, or broken:
Your legitimate emails get marked as spam or blocked entirely. You might be sending perfectly professional emails that never make it to the inbox.
Your domain becomes easier to spoof. Scammers can send emails that appear to come from your company, damaging your reputation and potentially targeting your clients.
You fail DMARC alignment. DMARC relies on SPF. If your SPF record is wrong, your DMARC policy can’t work properly, which means you’re not fully protected against impersonation.
You look less professional. When emails from your domain consistently land in spam, people notice. It doesn’t exactly inspire confidence.
The tricky part is that SPF problems aren’t always obvious. Sometimes emails go through fine. Sometimes they don’t. It depends on how strict the receiving mail server is and how badly your SPF record is broken.
The “Too Many DNS Lookups” Problem
Here’s where SPF gets properly annoying.
Your SPF record lists the mail servers authorized to send email on your behalf. But many of those services (like Microsoft 365, Mailchimp, or your CRM platform) don’t just have one or two mail servers – they have dozens, and those server lists can change.
To handle this, your SPF record includes references to these services, and when an email is checked, the receiving server has to look up each of those references. The problem? There’s a hard limit of 10 DNS lookups per SPF check.
Go over that limit, and your SPF record breaks. Not partially – it fails entirely. Your emails start getting blocked or marked as spam, and you might not even know why.
This happens more easily than you’d think:
- Microsoft 365: 1-2 lookups
- Google Workspace: 3 lookups
- Mailchimp: 1 lookup
- Your CRM platform: 1-2 lookups
- Your website contact form: 1 lookup
- Any other mail-sending service you use: 1+ lookup each
Add those up, and you’ve hit the limit before you know it. Every time you add a new service that sends email on your behalf, you’re pushing closer to that cliff edge.
What Is SPF Flattening?
SPF flattening is the solution to the lookup limit problem.
Instead of your SPF record pointing to external services (which each require lookups), SPF flattening replaces those references with the actual IP addresses of the mail servers. This reduces the number of lookups required and keeps you well under the 10-lookup limit.
The catch? Those IP addresses change. When Microsoft adds a new mail server or your marketing platform updates their infrastructure, your SPF record needs to be updated too. If it isn’t, your emails start failing again.
This is why SPF flattening isn’t a “set it and forget it” task – it requires ongoing monitoring and updates. Most businesses either don’t realize this or don’t have the time to stay on top of it.
The Three Ways to Handle SPF
There are essentially three approaches to managing your SPF record:
DIY: You set up and maintain your SPF record yourself. This works if you’ve got in-house IT expertise, you’re only using one or two email-sending services, and you’re comfortable monitoring DNS records. For most businesses, this isn’t realistic.
Hope Your Email Provider Handles It: Some email providers (like Microsoft 365 or Google Workspace) give you an SPF record to add to your DNS, but they don’t manage what else you add to it. If you’re using multiple services that send email on your behalf, you’re still on your own for combining them correctly and staying under the lookup limit.
Use a Hosted SPF Service: This is where a service (like ours) monitors your SPF record continuously, flattens it automatically, and updates it whenever the underlying mail servers change. You get the benefit of proper SPF compliance without needing to think about it.
How We Manage SPF for Our Partners
When we set up hosted SPF for a business, here’s what actually happens:
We audit every service you use that sends email on your behalf – your email platform, CRM, marketing tools, website forms, accounting software, anything that touches email.
We build an SPF record that covers all of them while staying well under the 10-lookup limit using SPF flattening.
We monitor it continuously. When Microsoft updates their mail servers or when you add a new service, we catch it and update your SPF record accordingly.
We handle it alongside DKIM, DMARC, and the rest of your email security setup so everything works together properly.
The goal isn’t just to get your SPF record working today – it’s to keep it working without you having to think about it. You shouldn’t need to become a DNS expert just to make sure your emails are delivered.
What Happens If You Ignore SPF?
In the short term, you might not notice anything. Some emails will get through fine. Others won’t, and you’ll only find out when someone mentions they didn’t receive something.
Over time, though, the problems compound:
More emails land in spam as mail providers get stricter about authentication.
Your domain reputation suffers, making deliverability worse even for emails that technically pass SPF.
You’re more vulnerable to domain spoofing, which can damage your business relationships and your brand.
You can’t implement DMARC properly, which means you’re missing out on the strongest protection against email impersonation.
The worst part is that these problems build gradually. By the time you realize SPF is broken, you’ve already lost emails, opportunities, and trust.
Is Hosted SPF Worth It?
For most businesses, yes.
If you’re using more than one or two services that send email on your behalf, managing SPF correctly is fiddly, time-consuming, and easy to get wrong. Hosted SPF takes that off your plate.
It’s particularly valuable if:
- You’ve added multiple email-sending services over time (CRM, marketing automation, website forms, etc.)
- You’re not sure if your current SPF record is correct or complete
- You’ve had emails mysteriously land in spam or get blocked
- You’re implementing or planning to implement DMARC
- You don’t have in-house IT staff who monitor DNS records
The alternative is either accepting broken SPF (and the deliverability problems that come with it) or spending your time learning about DNS lookups and mail server IP ranges. Neither is ideal.
How AOIT Networks Approaches It
We check your current SPF record, confirm whether it is within the lookup limit, and look at it alongside the rest of your email authentication setup, rather than treating SPF as an isolated problem.
If a properly managed, flattened SPF record makes sense for your business, we will explain what that involves. If your current setup is fine as it is, we will tell you that too. Get in touch and we will take a look.
Got Questions About Your IT?
Questions about your setup? Wondering if there's a better way to do things? We're always happy to have a no-pressure conversation about your IT needs.
No sales pitch. No obligation. Just straightforward advice from people who genuinely care about getting it right.

