Skip to Main Content
SPF Flattening

Goodbye to the 10-lookup headache. SPF flattening fixes it for good.

SPF flattening collapses your nested includes so the record evaluates under SPF's 10-DNS-lookup limit. Palisade puts every sender behind one hosted include that stays inside the limit as you add tools.

What SPF Flattening helps you accomplish

One include, every sender

Replace the pile of nested includes with a single Palisade-hosted include. Your public record gets shorter; the senders behind it don't.

No more permerror

Past ten lookups, receivers return permerror: SPF fails, alignment fails, and DMARC treats your own mail as suspect. Flattening keeps the evaluation inside the budget.

Room to add the next tool

A new sending service no longer costs you a lookup you don't have. Confirm the sender in Palisade and the hosted include carries it.

Trusted by leading brands worldwide

Partner LogoPartner LogoPartner LogoPartner LogoPartner LogoPartner LogoPartner LogoPartner LogoPartner LogoPartner LogoPartner LogoPartner LogoPartner LogoPartner LogoPartner LogoPartner LogoPartner LogoPartner LogoPartner LogoPartner LogoPartner LogoPartner LogoPartner LogoPartner LogoPartner LogoPartner LogoPartner LogoPartner LogoPartner LogoPartner LogoPartner LogoPartner LogoPartner LogoPartner LogoPartner LogoPartner Logo
How it works

From a bloated record to one hosted include

The flattening runs behind a single include you publish once.

1

Point SPF at Palisade

Publish one TXT record with the Palisade include at your DNS provider. That's the only record you maintain by hand from then on.

2

Senders resolve behind it

The senders you've confirmed in Palisade make up the hosted include. Nothing is in your SPF that you haven't reviewed.

3

Lookups collapse

Receivers spend one lookup on the include instead of a dozen on nested ones. The whole record evaluates inside SPF's budget.

4

Changes stay reviewed

Adding or removing a sender is an explicit change in Palisade, drafted by the Agent and approved by you, not a hand-edit at the registrar.

What's included

What hosted SPF gives you

The lookup budget, visible

See how many DNS lookups your record spends and which includes spend them, before receivers start returning permerror. An AI assistant connected over MCP reads the same live chain with the get_spf tool.

Redundant managed DNS

The hosted include is served on redundant managed DNS, so the record receivers resolve is fast and consistently available.

Built from confirmed senders

The include reflects the sending sources you've verified from real report traffic, not a hand-maintained list that drifts out of date.

Alignment-aware

SPF that passes but doesn't align still fails DMARC. Palisade tracks both, so the record serves enforcement, not just the syntax check.

Fixes drafted when SPF breaks

A sender failing SPF becomes a ticket with the change drafted, the same review-and-approve loop as the rest of Palisade.

Last seen, per sender

Every authorized sender shows the last day mail passed SPF through it, and the ones silent for a year say so. Trimming the record stops being a guess about which include is still carrying mail.

Check any record free

The free SPF checker counts lookups and flags over-limit records on any domain, a useful audit before you flatten.

Proof from teams managing authentication at scale.The operational payoff of removing manual work.

Read more
Deliverability: 21% more meetings booked. How gaiia stopped landing in spam.

Deliverability

21% more meetings booked.How gaiia stopped landing in spam.

We increased our meetings booked by 21% and slept better at night knowing our emails are now secured

Marc-André Campagna, CEO, gaiia

Read the case study
gaiia's trade-show booth, its overhead banner reading "grow better with gaiia" above a mint-green wall that says "If your BSS is kind of BS, talk to us."
Questions

SPF Flattening: FAQ

What is SPF flattening?

SPF allows at most ten DNS lookups per evaluation, and every include, a, mx, or redirect mechanism spends one, nested includes spend more behind your back. Flattening resolves that tree into a compact record so receivers can evaluate it inside the budget. Palisade hosts the flattened result behind one include you publish once.

What happens if my record is over the limit?

Receivers stop evaluating and return permerror. That means SPF neither passes nor fails cleanly, and under DMARC, mail that can't pass SPF has to lean entirely on DKIM. If DKIM has a gap too, your own legitimate mail starts failing authentication.

Why does this matter for DMARC?

DMARC passes when SPF or DKIM passes and aligns with your domain. An over-limit SPF record silently removes one of those two paths for every sender you have. Getting the record under the limit is often one of the first tickets on the way to enforcement.

Is flattening safe when providers change their IPs?

That's the classic risk of do-it-yourself flattening: you copy a provider's addresses once and they drift. With hosted SPF the record behind the include is maintained by Palisade, so you're not hand-tracking provider changes at the registrar.

Do I have to change DNS providers?

No. You publish one TXT record with the Palisade include at your existing provider. Same as any other SPF record. Your registrar and DNS host stay exactly where they are.

Do I control what's in the hosted record?

Yes. The include is built from the senders you've confirmed in Palisade. New sources show up as tickets to review, and nothing joins your SPF without your approval.

Put your SPF under the limit for good

1 domain free up to 1,000 emails/month