Goodbye to the 10-lookup headache. SPF flattening fixes it for good.
SPF flattening collapses your nested includes so the record evaluates under SPF's 10-DNS-lookup limit. Palisade puts every sender behind one hosted include that stays inside the limit as you add tools.
What SPF Flattening helps you accomplish
One include, every sender
Replace the pile of nested includes with a single Palisade-hosted include. Your public record gets shorter; the senders behind it don't.
No more permerror
Past ten lookups, receivers return permerror: SPF fails, alignment fails, and DMARC treats your own mail as suspect. Flattening keeps the evaluation inside the budget.
Room to add the next tool
A new sending service no longer costs you a lookup you don't have. Confirm the sender in Palisade and the hosted include carries it.
Trusted by leading brands worldwide




































From a bloated record to one hosted include
The flattening runs behind a single include you publish once.
Point SPF at Palisade
Publish one TXT record with the Palisade include at your DNS provider. That's the only record you maintain by hand from then on.
Senders resolve behind it
The senders you've confirmed in Palisade make up the hosted include. Nothing is in your SPF that you haven't reviewed.
Lookups collapse
Receivers spend one lookup on the include instead of a dozen on nested ones. The whole record evaluates inside SPF's budget.
Changes stay reviewed
Adding or removing a sender is an explicit change in Palisade, drafted by the Agent and approved by you, not a hand-edit at the registrar.
What hosted SPF gives you
The lookup budget, visible
See how many DNS lookups your record spends and which includes spend them, before receivers start returning permerror. An AI assistant connected over MCP reads the same live chain with the get_spf tool.
Redundant managed DNS
The hosted include is served on redundant managed DNS, so the record receivers resolve is fast and consistently available.
Built from confirmed senders
The include reflects the sending sources you've verified from real report traffic, not a hand-maintained list that drifts out of date.
Alignment-aware
SPF that passes but doesn't align still fails DMARC. Palisade tracks both, so the record serves enforcement, not just the syntax check.
Fixes drafted when SPF breaks
A sender failing SPF becomes a ticket with the change drafted, the same review-and-approve loop as the rest of Palisade.
Last seen, per sender
Every authorized sender shows the last day mail passed SPF through it, and the ones silent for a year say so. Trimming the record stops being a guess about which include is still carrying mail.
Check any record free
The free SPF checker counts lookups and flags over-limit records on any domain, a useful audit before you flatten.
Proof from teams managing authentication at scale.The operational payoff of removing manual work.
Read moreDeliverability
21% more meetings booked.How gaiia stopped landing in spam.
“We increased our meetings booked by 21% and slept better at night knowing our emails are now secured”
Marc-André Campagna, CEO, gaiia

SPF Flattening: FAQ
What is SPF flattening?
SPF allows at most ten DNS lookups per evaluation, and every include, a, mx, or redirect mechanism spends one, nested includes spend more behind your back. Flattening resolves that tree into a compact record so receivers can evaluate it inside the budget. Palisade hosts the flattened result behind one include you publish once.
What happens if my record is over the limit?
Receivers stop evaluating and return permerror. That means SPF neither passes nor fails cleanly, and under DMARC, mail that can't pass SPF has to lean entirely on DKIM. If DKIM has a gap too, your own legitimate mail starts failing authentication.
Why does this matter for DMARC?
DMARC passes when SPF or DKIM passes and aligns with your domain. An over-limit SPF record silently removes one of those two paths for every sender you have. Getting the record under the limit is often one of the first tickets on the way to enforcement.
Is flattening safe when providers change their IPs?
That's the classic risk of do-it-yourself flattening: you copy a provider's addresses once and they drift. With hosted SPF the record behind the include is maintained by Palisade, so you're not hand-tracking provider changes at the registrar.
Do I have to change DNS providers?
No. You publish one TXT record with the Palisade include at your existing provider. Same as any other SPF record. Your registrar and DNS host stay exactly where they are.
Do I control what's in the hosted record?
Yes. The include is built from the senders you've confirmed in Palisade. New sources show up as tickets to review, and nothing joins your SPF without your approval.
Put your SPF under the limit for good
1 domain free up to 1,000 emails/month



