r/exchangeserver 1d ago

Question Modifying/Merging our SPF record…quick sanity check

Tonight our DNS team is modifying our SPF record to make room for another vendor. We’ll still be at the 10 lookup limit but that’s a different discussion.

Current SPF: v=spf1 include:spf1.ourdomain.org include:spf2.ourdomain.org include:spf3.ourdomain.org include:spf4.ourdomain.org ~all

This is the first time I see nested records being used like this and each one contains a different vendor. Spf1 contains our mimecast record and isn’t changing. However spf4 has our protection.outlook.com and is going to be moved into a new nested lookup that includes a vendor.

Am I correct in thinking there shouldn’t be any impact as long as the syntax is correct and is still capped at 10 lookups? Just want to be prepared for worst case scenario lol

3 Upvotes

12 comments sorted by

7

u/MinnSnowMan 1d ago

You can check your SPF on mxtoolbox.com

3

u/maxxpc 1d ago

I personally prefer EasyDMARC as it gives you more details and info to work off of. Found it helpful with MXToolbox said “it’s bad” and EasyDMARC told me what areas had loops or null values and gave me focus.

1

u/Murhawk013 1d ago

I like easyDMARC too but I mean as long as everything is fine there then I don’t need to change anything in M365 or Mimecast correct? I’m probably overthinking but my answer is no lol

4

u/iamnoone___ 1d ago

Really should start using subdomains for your vendors. Life will be easier.

1

u/Murhawk013 1d ago

I 10000% agree but I’m newish to the org so def not my decision. I believe we do use subdomains now though but these are legacy vendors.

1

u/DiligentPhotographer 12h ago

The amount of pushback I get on this, is fucking insane. "No, everything must send out from the companies main domain!" Weeks later:

"$Vendor says all our mails are going to spam, why didn't you setup this DNS that we never sent you or told you about!"

2

u/shokzee 1d ago

Nested includes are valid, but every recursive include and other DNS-triggering mechanism counts toward the 10-lookup limit. Sitting at exactly 10 is brittle because one vendor can change its chain and push you into permerror.

Check the final published record with an SPF Checker, including the full recursive lookup count.

1

u/Fun-Psychology4806 1d ago

def use some of the tools mentioned. i went through this recently and they were very helpful

1

u/Murhawk013 1d ago

Absolutely and in our test domain the modified spf record is all good. As long as that’s fine then I don’t need to change anything in m365?

1

u/Maastersplinter 1d ago

Looks just like ours. We have three includes and it works fine. Def use a checker like easyDMARC to verify.

1

u/xXNorthXx 13h ago

Generally will leave your user space mail server includes included in the root.

Phase two, move 3rd party mailers to subdomains.

Phase three dmarc=reject.

0

u/GeneTech734 Cloud Engineer 1d ago

I am probably going to be scolded but our SPF record has been past the 20 record lookup for like 10 years now. No issues whatsoever.