What does this mean?
PermError indicates a permanent policy evaluation error, rather than simply a sender that was not authorized. Multiple SPF policies, malformed terms or excessive DNS-dependent evaluation can be involved. Retrying unchanged messages usually does not repair an invalid published policy.
What should I check first?
Save the exact receiver result and query TXT at the envelope domain it evaluated. Count matching v=spf1 policies, not all TXT records. Other TXT data can be legitimate. Compare the current zone with a backup if the error began after a provider or nameserver change.
How can I diagnose the cause?
Review spelling and syntax against the sending providers’ instructions. Follow include and redirect dependencies through provider diagnostics: an apparently short record can expand into many lookups. The browser explainer does not evaluate those chains, so a lack of local warnings does not prove the full policy is valid.
How do I fix it safely?
Consolidate duplicate SPF policies into one provider-reviewed record and remove obsolete authorized senders after confirming they are no longer used. Do not flatten provider-controlled address lists into a permanent static copy without an ongoing update plan. Save the original record and plan rollback before changing production email.
Verify the fix and know when to contact your provider
Test every legitimate sending service after the correction. If evaluation still fails, ask the mail provider for the complete failure reason and expanded lookup path. Supply the domain, published policy, affected message time and redacted result. Keep DKIM and DMARC records intact while repairing SPF.
Work through these checks in order
- Count only the TXT records beginning with the SPF version identifier at the evaluated name. Two such policies are a problem even if each looks reasonable on its own.
- Ask the mail provider to inspect full include and redirect evaluation, not just the visible policy length. The tool’s local term explanations do not prove compliance with evaluation limits.
- Consolidate approved sources into one reviewed policy, then test each source. Record the corrected result and keep a backup of the previous values in case the change needs rollback.
Which tool can help?
SPF DNS record checker · SPF record explainer
DNS tools show one resolver’s public answers. Record explainers do not authenticate a message, and calculators do not monitor a server. Use the evidence alongside your provider’s logs.