SPF ends in ~all (softfail)
Check id: spf.all_soft · fix effort: low
What it means
Your SPF record ends in ~all, so unknown senders only get softly flagged instead of rejected. That's fine if DMARC is enforcing. If it isn't, tighten this up.
The technical detail
~all alone lets forged mail through with a softfail. Acceptable with DMARC at p=quarantine or p=reject, otherwise move to -all.
How to fix it
- If DMARC is at
p=noneor missing, prioritize DMARC enforcement. - Once all legitimate senders are confirmed in SPF, tighten to
-all.
Does your domain have this problem?
Run a free scan, takes about ten seconds.