Outbound mail from a professional services firm started failing to specific recipients with no obvious pattern — some providers receiving normally, others silently dropping. Support tickets with Microsoft and the firm's mail vendor found nothing.
Intermittent delivery failures with no error log are one of the harder mail problems to diagnose. One of the most common causes is an SPF record that was built incrementally and never audited.
Delivery failing to specific recipients, no pattern
The firm used seven cloud services that sent email on their behalf — CRM, accounting, support desk, marketing, transactional notifications, invoicing, and direct Exchange Online. Each had been added to the SPF record as it was set up, with no audit of the total DNS lookup count. The resulting include chain resolved to 14 DNS lookups — well above the RFC 7208 limit of 10. Providers that enforced the limit strictly were returning permerror and dropping the mail. Providers that were lenient were accepting it. Hence the apparently random pattern of failures.
SPF audit and restructure
- Mapped the full SPF include chain, counting all DNS lookups
- Identified two deprecated service includes — services the firm had stopped using
- Removed deprecated includes and restructured remaining ones to reduce nesting
- Flattened two high-lookup includes to direct IP ranges, bringing total to 7
- Verified the restructured record with lookup-count tooling before publishing
- Added SPF evaluation monitoring to detect future drift
Delivery restored, lookup count under limit
- SPF lookup count reduced from 14 to 7
- Intermittent delivery failures resolved within 24 hours of DNS propagation
- DMARC pass rate increased from 61% to 99.4% in the following reporting period
- Monitoring in place to alert on SPF evaluation failures before they become delivery problems
SPF records accumulate. Every SaaS tool added is another include. Auditing this regularly is infrastructure maintenance — not a one-time setup task.
Frequently asked questions
- What caused the intermittent delivery failures?
- An SPF record that had grown past the RFC limit. The firm used seven cloud services that sent email on their behalf - CRM, accounting, support desk, marketing, transactional notifications, invoicing and Exchange Online - each added as it was set up, with no audit of the total DNS lookup count. The record resolved to 14 lookups.
- Why did only some recipients reject the mail?
- Because providers differ in how strictly they enforce the 10-lookup limit. Some received normally while others silently dropped the mail, which is what made the pattern look random and why support tickets with Microsoft and the firm's mail vendor found nothing.
- Why is this hard to diagnose?
- Intermittent delivery failures with no error log are one of the harder mail problems to diagnose. There is no bounce naming the cause, and the record itself looks valid until you trace the full include chain and count the resulting lookups.
- How was it fixed?
- By auditing and restructuring the SPF record to bring the lookup count back under the limit. The general method - counting lookups, removing retired includes and flattening where appropriate - is covered in the SPF 10-lookup limit article.