Mimecast and the SPF lookup limit
9 of 10 lookups
include:_netblocks.mimecast.com
— was 6, now 9.
Nine of your ten DNS lookups, spent before any of your own senders are considered. The most expensive record we measure, and it has grown.
Mimecast's headline include is a directory rather than a list of addresses. It contains nothing but five further includes, one per region it operates in: Europe, the United States, South Africa, Germany and Australia. Each of those resolves to a real list of netblocks, and a receiving server walks all of them.
So a customer sending only from Australia still pays for the European, American, South African and German netblocks on every single evaluation. Nine terms of a ten term budget, for one vendor, to authorise servers that will never send your mail.
It has also moved in the wrong direction. The same include cost six lookups when the Expurgate list was compiled; it costs nine now, because Mimecast added regions. Nothing warned anyone: a record that fitted last year quietly stopped fitting.
What it costs by region
| Region | Lookups | Include |
|---|---|---|
| All regions as published | 9 | _netblocks.mimecast.com |
| Europe | 1 | eu._netblocks.mimecast.com |
| United States | 1 | us._netblocks.mimecast.com |
| Australia | 1 | au._netblocks.mimecast.com |
| Germany | 1 | de._netblocks.mimecast.com |
| South Africa | 1 | za._netblocks.mimecast.com |
Naming your own region saves 8 lookups. Mimecast documents these includes, so this is a supported change rather than a trick.
What to do
- Publish your region's include instead of the parent. Mimecast documents these, and the one for your region authorises exactly the servers that actually send your mail. Nine lookups become one.
- Check which region your tenant is in before you change anything. If Mimecast migrates you to another region later, a hardcoded regional include stops authorising your mail, and SPF failures are not something you get told about.
- If you would rather not track that, hand the whole record to SPF Guru and keep the parent include. It is read on your behalf and costs a receiving server one lookup either way.
Check your own record
These numbers are what the include costs on its own. What matters is the total across your whole record, because the ten term limit applies to the evaluation, not to any one vendor.
Expand
_netblocks.mimecast.com
to see the 8 lookups nested inside
it. The tree reports 8 rather than 9 because it
counts the terms in that record; the include: that reaches it is
the one your own record adds.
Check your own domain to see what the whole record costs and get a replacement that fits.
Measured, not quoted. 9
lookups for
include:_netblocks.mimecast.com, evaluated against live DNS on
2026-09-09 with the same engine behind the
SPF checker. Vendor records move without announcement,
so this is re-checked weekly rather than written down once.
Related
- Freshdesk — 7 lookups
- Oracle NetSuite — 5 lookups
- Every vendor we measure