Blog article

14 Sep 20265 minutes read

SendmarcSendmarc

Null DNS Lookup: Causes, Detection, and Remediation

Digital illustration of a broken DNS lookup disrupting an SPF authentication chain

Null DNS lookup overview:

  • A null DNS lookup produces a PermError or TempError and can cause legitimate email to fail.
  • NODATA is the most common cause: the included domain exists, but the DNS TXT record is missing.
  • A broken include quietly removes one of DMARC's two authentication paths.
  • SPF records drift as vendors change infrastructure, so ongoing monitoring can catch a broken include before it becomes an issue.
  • NODATA (NOERROR/NODATA): The domain exists, but there's no DNS TXT record.
  • NXDOMAIN: The domain doesn't exist at all.
  • SERVFAIL, timeouts, and other transient DNS failures: Treated as DNS failures.
  1. Retrieve and parse your full SPF record. Run your domain through Sendmarc's SPF record checker to pull the current record. Isolate every include mechanism and list them.
  2. Query each included domain. Run each include value through the same record checker. A blank result (NODATA) or an NXDOMAIN status is a DNS lookup failure. Note which include returned it.
  3. Correlate against your authorized sender inventory. For each broken include, determine which sending service it was supposed to authorize. Check whether that service is still active, whether it has issued a new SPF include value, or whether the service has been decommissioned entirely.
  • If the vendor has a new include value: Replace the broken include with the current one.
  • If the service is decommissioned: Remove the include entirely.
  • If the include is from a third-party record you don't control: Contact the vendor directly.
  • If the domain still exists but the TXT record is missing: May indicate an internal DNS issue. Check with the team managing the DNS.
  • Audit all SPF includes and their full chains quarterly, or after any vendor onboarding or offboarding
  • Add SPF record change notifications to your DNS change management process
  • Subscribe to vendor communication channels to receive advance notice of infrastructure changes affecting SPF
  • Test SPF for every domain in your portfolio, not just primary sending domains, since subdomains and parked domains carry risk too
  • Monitor DMARC aggregate reports for SPF failure spikes by sending source IP; these can indicate a broken include before it becomes critical
  • Build a repeatable workflow that checks SPF includes across every domain in your portfolio on a defined schedule

Share

Get our latest blogs delivered to your inbox each month

Leave a reply

Your email address will not be published. Required fields are marked *

Useful Tools

DNS Lookup
Free toolNo sign-up

DNS Lookup

Use Sendmarc's DNS lookup tool to instantly analyze domain records, verify configurations, and detect DNS issues for better performance.

Email Header Analyzer
Free toolNo sign-up

Email Header Analyzer

Quickly analyze email headers with Sendmarc’s email header analyzer. Check SPF, DKIM, and DMARC results, detect phishing, and improve email deliverability.

Domain Checker
Free toolNo sign-up

Domain Checker

Use the Sendmarc domain checker to test against malicious use - free, no sign-up required, with results in under a minute.