Evidence and research

What a Large SPF Study Reveals About Lookup Errors

By EmailmetryReviewed 2 min read

A large historical SPF study found that some published records exceeded the lookup limit when fully resolved. That finding needs care: a scan of every reference is different from a check for one sender.

Counting domains with SPF records tells us how widely SPF is published. It does not establish that those records work for every intended sender.

A record may omit a legitimate sending service, authorise one that is no longer used, or require too many lookups for some messages.

What a large study found

The USENIX Security 2024 paper SPF Beyond the Standard studied about 176 million domains across .com, .org, .net and .se between October 2021 and March 2023.

In its final snapshot, roughly 55 million domains had SPF records. When fully resolving the records, the researchers flagged 6.5% for exceeding the lookup limit. The paper, section 3.3.1

These are historical observations about domains in the study, not a current failed-message rate.

The distinction matters because a full scan follows references that a particular sender might never reach. SPF evaluates a record in order and can stop at an earlier match. A large reference tree can therefore produce different outcomes for different sending addresses. SPF evaluation rules

The record at the top can hide more lookups

A short SPF record can refer to providers whose records contain further references.

SPF permits ten DNS-querying terms during an evaluation, including those reached through nested records. A message that needs more receives a permanent error. Counting only the includes visible in the domain’s own record can miss that cost. SPF lookup limit

What the finding tells you to inspect

For your own domain, inspect the reference tree and identify the path each intended sender takes. The worked lookup example explains why one sender can pass early while another reaches a limit.

The SPF checker can inspect the published record and references. It does not reproduce the study or establish a current failure rate for your messages. Received-message results supply a different piece of evidence.

Presence is a useful starting point

A domain that sends no email can correctly publish a policy authorising no senders. A domain that sends through several applications needs a policy that reflects those applications. Both count as having SPF, despite serving different purposes.

Adoption figures help describe deployment. Assessing an individual domain requires a closer question: can its intended senders pass the relevant policy without exceeding SPF’s limits?

Sources and further reading

Sources reviewed 12 September 2026.