SPF Flattening

SPF flattening that stays under the 10-lookup limit

SPF flattening resolves the include chain in your record down to a compact record, so evaluation stays under SPF's 10-DNS-lookup limit. Every ESP, CRM, and helpdesk you add spends DNS lookups from SPF's budget of ten — and at eleven, SPF stops evaluating and legitimate mail starts failing. Palisade flattens your senders into one hosted include that stays inside the limit as your stack grows.

One include, every sender

Replace the pile of nested includes with a single Palisade-hosted include. Your public record gets shorter; the senders behind it don't.

No more permerror

Past ten lookups, receivers return permerror — SPF fails, alignment fails, and DMARC treats your own mail as suspect. Flattening keeps the evaluation inside the budget.

Room to add the next tool

A new sending service no longer costs you a lookup you don't have. Confirm the sender in Palisade and the hosted include carries it.

Trusted by leading brands worldwide

Partner LogoPartner LogoPartner LogoPartner LogoPartner LogoPartner LogoPartner LogoPartner LogoPartner LogoPartner LogoPartner LogoPartner LogoPartner LogoPartner LogoPartner LogoPartner LogoPartner LogoPartner LogoPartner LogoPartner LogoPartner LogoPartner LogoPartner LogoPartner LogoPartner LogoPartner LogoPartner LogoPartner LogoPartner LogoPartner LogoPartner LogoPartner LogoPartner LogoPartner LogoPartner LogoPartner Logo
How it works

From a bloated record to one hosted include

The flattening runs behind a single include you publish once.

1

Point SPF at Palisade

Publish one TXT record with the Palisade include at your DNS provider. That's the only record you maintain by hand from then on.

2

Senders resolve behind it

The senders you've confirmed in Palisade make up the hosted include. Nothing is in your SPF that you haven't reviewed.

3

Lookups collapse

Receivers spend one lookup on the include instead of a dozen on nested ones — the whole record evaluates inside SPF's budget.

4

Changes stay reviewed

Adding or removing a sender is an explicit change in Palisade, drafted by the Agent and approved by you — not a hand-edit at the registrar.

What's included

What hosted SPF gives you

The lookup budget, visible

See how many DNS lookups your record spends and which includes spend them, before receivers start returning permerror.

Redundant managed DNS

The hosted include is served on redundant managed DNS, so the record receivers resolve is fast and consistently available.

Built from confirmed senders

The include reflects the sending sources you've verified from real report traffic — not a hand-maintained list that drifts out of date.

Alignment-aware

SPF that passes but doesn't align still fails DMARC. Palisade tracks both, so the record serves enforcement, not just the syntax check.

Fixes drafted when SPF breaks

A sender failing SPF becomes a ticket with the change drafted — the same review-and-approve loop as the rest of Palisade.

Check any record free

The free SPF checker counts lookups and flags over-limit records on any domain — a useful audit before you flatten.

Teams that put the Agent to work.From one domain to thousands.

Read more
Agent: The work, in a fraction of the time. Why CDT Connexion moved every client onto Palisade.

Agent

The work, in a fraction of the time.Why CDT Connexion moved every client onto Palisade.

I've migrated all my clients from PowerDMARC. The agent was so powerful it allowed us to do the work in a fraction of the time.

Marc-Olivier Hardy — VP & CTO, CDT Connexion

See Palisade for MSPs
Questions

SPF Flattening: FAQ

Put your SPF under the limit for good

1 domain free up to 1,000 emails/month