SPF permerror: the silent policy killer
RFC 7208 Section 2.6.7 is unforgiving
exceed 10 DNS lookups and your SPF result flips to permerror
which most receivers treat as a fail
the insidious part: you can be at exactly 10 lookups today, then a vendor adds a nested include and you're at 12 tomorrow
no notification, no warning
you either use sub-domain for sending emails, or you flatten them



