SPF 记录超过 10 次 DNS 查询后会发生什么?
RFC 7208 §4.6.4 规定 SPF 评估过程中最多执行 10 次 DNS 查询(不包括 a/mx/ptr/exists 的基础查询本身,但 include:、redirect=、a:/mx: 解析出的域名会累计)。超出 10 次时,接收方 MTA 直接返回 PermError(永久错误),SPF 结果变为 permerror(相当于 fail)。
1. 确认是否超限:dig TXT yourdomain.com +short 把 SPF 记录复制到 https://spftool.net/count/ 或本地用 spfquery:spfquery --domain=yourdomain.com
如果返回 permerror to many DNS lookups,就是超了。
2. 精简 SPF 的常用方法:
— 合并 include:将多个第三方邮件供应商的 IP 直接写入 ip4: 机制而非继续 include:(例如 SES、SendGrid 的固定出站 IP)。
— 检查嵌套的 include 链:include:spf.protection.outlook.com 内部可能已包含 3-4 次 lookup,加上其他供应商很容易超限。
— 避免冗余的 include:exists:exists: 也算一次查询。
3. 终极方案:SPF flattening:
用脚本周期性展开所有 include: 为纯 ip4:/ip6: 列表,发布为静态 SPF 记录。工具:n8ec6/spf-flatten 或 spfvalidate -flatten。
4. 特别提醒:redirect= 也会消耗查询计数,且如果目标域本身也超标,则实锤 PermError。
RFC 7208 §4.6.4 (DNS Lookup Limits) · RFC 7208 §5 (Record Evaluation) · RFC 7208 §10.1 (Macro Expansion)
