SPF ends in ~all (softfail)

Check id: spf.all_soft · fix effort: low

What it means

Your SPF record ends in ~all, so unknown senders only get softly flagged instead of rejected. That's fine if DMARC is enforcing. If it isn't, tighten this up.

The technical detail

~all alone lets forged mail through with a softfail. Acceptable with DMARC at p=quarantine or p=reject, otherwise move to -all.

How to fix it

  1. If DMARC is at p=none or missing, prioritize DMARC enforcement.
  2. Once all legitimate senders are confirmed in SPF, tighten to -all.

Does your domain have this problem?

Run a free scan, takes about ten seconds.