Which SPF Mistakes Hurt Cold Email Deliverability?
A mailtester.com deep-dive reveals how wrong sender domains, syntax errors, and DNS lookup overflows silently push cold emails into spam, and how to fix them this week.
Three SPF mistakes do most of the damage: the wrong sender domain in the record, a missing include for the tool you send through, and more than 10 DNS lookups. A recent mailtester.com analysis found that SPF misconfigurations are one of the most common causes of deliverability drops across the sending domains its team audits, often invisible until a campaign's reply rate falls off a cliff.
This is not a theoretical problem. A broken SPF record removes one of the two authentication checks inbox providers run, and bulk senders are expected to pass both. You can have a clean IP reputation and a warm domain and still lose inbox placement because of a single malformed include.
Why SPF Still Matters in 2026
Google and Yahoo tightened bulk sender requirements in February 2024, Microsoft followed in May 2025, and none of them has relaxed since. Google's sender guidelines require SPF or DKIM from every sender and both from anyone sending more than 5,000 messages a day to Gmail accounts.
DMARC is more forgiving than that. It passes when either SPF or DKIM passes and aligns with your From domain, so an aligned DKIM signature can carry a message past a broken SPF record. That is a safety net, not a reason to leave SPF broken: a bulk sender with failing SPF is out of compliance even while DMARC passes.
Cold email operators running multiple domains should care more about this than anyone. Each domain you spin up for outreach needs its own correctly configured SPF record. One copy-paste error or a forgotten ESP include can quietly cause weeks of wasted sends.
The Most Common SPF Misconfigurations
The mailtester.com analysis identified three failure patterns that appear repeatedly.
Wrong sender domain in the record. This happens when you copy an SPF record from one domain to another without updating the included domains for your actual sending infrastructure. You end up authorizing mail servers you do not use and missing the ones you do.
Missing include statements. If you send through an ESP like Instantly, Smartlead, or Quickmail, you need to include that provider's SPF mechanism in your DNS record. Adding a new sending tool without updating SPF is a very common miss. The message leaves through an authorized server, but your SPF record does not list that server, so the check fails.
Exceeding the 10 DNS-lookup limit. SPF validation caps at 10 DNS lookups per record evaluation. Each include:, a:, and mx: mechanism that requires a DNS query counts toward this limit. Many operators chain together includes from multiple ESPs, CRMs, and email security vendors and blow past 10 without realizing it. When the limit is exceeded, the result is a PermError, which receiving servers treat as a failure.
How a Broken SPF Record Causes Inbox Problems
The failure mode is not always outright rejection. Receiving servers handle SPF failures differently.
With -all, a message from a server the record does not list returns a hard fail, which some receivers reject outright. With ~all it returns a soft fail: the message is usually accepted, and the failure counts against it in filtering. A PermError from exceeding the DNS lookup limit stops evaluation before the all mechanism is reached, so the choice between -all and ~all does not help.
The practical outcome: your domain's sender reputation degrades over time. Reply rates drop. You might not notice for two or three weeks because early sends in a campaign go to engaged contacts who open quickly, masking the spam placement rate.
How to Audit Your SPF Record Before Your Next Send
Do this before you start any new campaign:
- Go to MXToolbox SPF checker and enter your sending domain. Look for any red or yellow flags.
- Count the total DNS lookups. MXToolbox will report this. If you are at 9 or 10, you are one new include away from a PermError.
- Cross-reference the includes in your record against every tool that sends mail on behalf of that domain. Your ESP, Google Workspace or Microsoft 365, any email security layer, any CRM that sends transactional mail. If any tool is missing, add its include.
- Check alignment. SPF is evaluated against the envelope sender (the Return-Path domain), and DMARC needs that domain to align with the domain in your
From:header. A mismatch fails SPF alignment even when SPF itself passes. - Send a test message through mail-tester.com and read the SPF, DKIM, and DMARC results for the server that actually sent it.
Tools to Verify SPF in Real Time
- MXToolbox is the standard starting point. It shows lookup counts, syntax errors, and whether includes resolve correctly.
- mail-tester.com tests a full send path by having you send an actual test message to an address it gives you, then scores the result. This catches misconfigurations that static DNS checkers miss because it tests the actual sending server.
- dmarcian has an SPF surveyor that maps out your full include tree visually, which helps when you have nested includes eating into your lookup budget.
When to Use SPF Flattening
SPF flattening converts all your dynamic includes into a flat list of IP addresses, which reduces your DNS lookup count to near zero. It sounds like an obvious fix for the 10-lookup problem, but there is a catch.
ESPs regularly add and change their IP ranges. A flattened record is a static snapshot. When your ESP adds new sending IPs and your record does not include them, you get the same failure you were trying to avoid. Flattening works if you use a service that automates the updates, such as AutoSPF, which monitors upstream changes and updates your DNS record automatically. Manual flattening without automated refresh creates a maintenance burden most operators do not keep up with.
Use flattening only if you are already near or past the 10-lookup limit and cannot reduce your includes by removing unused tools.
Deliverability Hygiene Checklist for Operators Running Multiple Domains
| Check | Frequency |
|---|---|
| Validate SPF with MXToolbox for each active sending domain | Before each new campaign |
| Send a test message through mail-tester.com and review the authentication results | Weekly |
| Audit includes against current tool stack (add/remove as tools change) | When adding or removing any ESP or tool |
| Check DNS lookup count, flag any domain at 8 or above | Monthly |
Confirm DMARC alignment for From: domain on each domain |
Before each new campaign |
If you run 10 sending domains, all 10 need this treatment. A misconfigured domain will drag reply rates and sender reputation regardless of how well the other 9 perform. SPF auditing takes under 15 minutes per domain. The cost of ignoring it is measured in burned domains and wasted sequences.
Sources
Tools mentioned
Cold email platform with unlimited mailbox connections, automated warmup, inbox rotation, and a built-in B2B lead database.
Cold email platform with unlimited mailboxes, ESP matching, white-label agency workspaces, and granular deliverability settings.
Cold email platform with unlimited senders and users, inbox rotation, free AutoWarmer warmup, and agency workspaces. Priced by contact and email volume, not seats.