SPF Lookup Counter Bug Undercounted GitHub's DNS Limit, Leaving It at the Edge
A developer discovered that their free SPF-checking tool incorrectly reported GitHub's SPF record as using 8 of the allowed 10 DNS lookups, when the true count is exactly 10. The error stemmed from counting only the include directives in GitHub's own record, without recursively evaluating the nested records inside each included domain. RFC 7208 caps SPF evaluation at 10 DNS-triggering lookups across the entire include tree, not just the top-level record. Two hidden lookups — one inside Salesforce's record via an exists: macro and one inside SendGrid's record via a nested include — pushed GitHub's real total to the limit. The developer has since corrected the tool to walk the full include tree and published a Node.js code snippet demonstrating how to count lookups accurately using Google's DNS-over-HTTPS API.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.


Discussion (0)
Log in to join the discussion and vote.
Log in