On this page
  1. What -all and ~all mean
  2. What receivers do with each
  3. How DMARC changes the choice
  4. What Google and Microsoft recommend
  5. Which ending to use
  6. How to change the ending
  7. Need hands-on help?
  8. Check your record
  9. Sources

An SPF record with a hard fail ends in -all: mail from any server the record doesn't list gets an SPF fail, and receiving servers may reject it, while ~all (soft fail) asks them to accept that mail but mark it as suspicious (Google Workspace (opens in a new tab)). Google (opens in a new tab) recommends ~all, and Microsoft (opens in a new tab) recommends -all for Microsoft 365 domains. RFC 9989 (opens in a new tab) warns that -all could get mail rejected before DMARC is checked, so review which services send for you before you pick either.

What -all and ~all mean

Sender Policy Framework (SPF) (opens in a new tab) lets a domain publish, in the Domain Name System (DNS) (opens in a new tab), which hosts may use its name, and receivers test the sending server against that list.

An SPF record is read one mechanism at a time, left to right. When a mechanism matches, processing ends and the qualifier in front of it becomes the result (RFC 7208 section 4.6.2 (opens in a new tab)):

Qualifier Result
+ (the default when none is written) pass
- fail
~ softfail
? neutral

The all mechanism always matches, so it goes last in a record as its explicit default, and mechanisms after it are never tested (section 5.1 (opens in a new tab)). In the standard's example, v=spf1 a mx -all, every server not matched earlier in the record gets a fail.

The two results differ in strength. A fail is an explicit statement that the server is not authorized to use the domain (section 2.6.4 (opens in a new tab)). A softfail is a weak statement that the server is probably not authorized, from a domain owner that has not published the stronger policy that would produce a fail (section 2.6.5 (opens in a new tab)).

Check your domain now

See the SPF, DKIM and DMARC records your domain publishes and what to fix first. Free, no account needed.

What receivers do with each

What happens to a message that fails SPF is a matter of the receiver's local policy (RFC 7208 section 8.4 (opens in a new tab)). A receiver that rejects it during the Simple Mail Transfer Protocol (SMTP) (opens in a new tab) transaction should use reply code 550 and, if supported, the status code 5.7.1. A receiver that accepts it should record the result in a Received-SPF or Authentication-Results header for later processing.

A softfail sits between fail and neutral. Receivers should not reject a message based on a softfail alone, but may give it closer scrutiny than normal (section 8.5 (opens in a new tab)).

In practice, receiving servers typically accept mail that soft fails but mark it as suspicious, and may reject mail that fails (Google Workspace (opens in a new tab)). Microsoft (opens in a new tab) describes the same split. With -all, mail from sources the record doesn't list should be rejected, and is typically discarded. With ~all, it should be accepted but marked: for example quarantined as spam, delivered to the Junk Email folder, or delivered to the Inbox with an identifier added to the subject or body. Either way, what actually happens depends on the receiving system.

A third ending, ?all (neutral), suggests no specific action. Microsoft treats it as a testing value and doesn't recommend it in production.

How DMARC changes the choice

SPF and DKIM on their own are not directly tied to the domain in the message's From address. DMARC (opens in a new tab) (Domain-based Message Authentication, Reporting, and Conformance) adds that link: a DMARC pass requires an SPF or DKIM pass for a domain aligned with the From domain (RFC 9989 section 1 (opens in a new tab)). DomainKeys Identified Mail (DKIM) (opens in a new tab) signs a message so the receiver can confirm the signed content has not changed. The DMARC fail guide covers alignment for sending services and forwarded mail.

SPF was intended to run early in the SMTP transaction, so a message can fail SPF before any of its content is sent, and some receivers might check SPF before any DMARC processing (RFC 9989 section 7.1 (opens in a new tab)). With -all, a message that fails SPF could then be rejected before DMARC runs, including one that would have passed DMARC through an aligned DKIM signature. Messages rejected that early never appear in aggregate DMARC reports.

DemiSignal's SPF record generator describes ~all as the usual ending when DMARC is in place, and -all as stricter, with some receivers then rejecting forwarded email before they check DKIM.

What Google and Microsoft recommend

Google (opens in a new tab) recommends ~all. With -all, messages that fail SPF are more likely to be rejected, and you can't use them to troubleshoot your SPF record; in that case Google recommends DMARC reports to identify all senders for your domain (Google Workspace (opens in a new tab)). If your SPF record isn't set up correctly, -all might also cause more of your messages to be sent to spam.

Microsoft (opens in a new tab) recommends -all for Microsoft 365 domains, because it also recommends DKIM and DMARC for the domain, and DMARC reports let you validate the results.

Which ending to use

Whichever you pick, the list has to be right first. Review your SPF record so you know which networks are authorized to send for you before you publish a DMARC policy, and review it again periodically (RFC 9989 section 7.1 (opens in a new tab)). If mail from a particular sender keeps going to spam, make sure that sender is in your SPF record (Google Workspace (opens in a new tab)).

  • You're still finding your senders. ~all is Google's (opens in a new tab) recommendation, and receivers should not reject a message on a softfail alone (RFC 7208 section 8.5 (opens in a new tab)).
  • You choose -all. Microsoft (opens in a new tab) recommends it for Microsoft 365 domains together with DKIM and DMARC. Expect that a message could be rejected on SPF alone before DMARC runs, even with an aligned DKIM signature, and that those rejections won't appear in aggregate reports.
  • The domain sends no email. Microsoft's example for domains not used for email is v=spf1 -all, which authorizes no one to send. Each subdomain needs its own SPF record.

How to change the ending

Edit the record you have; don't add a second one. A domain must publish exactly one SPF record, and two make SPF fail with an error (SPF record generator).

  1. In your DNS provider, find the TXT record on the root of your domain that starts with v=spf1.
  2. Change its ending to ~all or -all, and save that one record.
  3. Wait for DNS. Changes usually show within an hour; some providers take up to 48 hours.
  4. Run the free check to confirm the record.

The generator builds a full record from the services that send email for your domain, and for email from servers not listed lets you choose to mark it as suspicious (~all) or reject it (-all).

Need hands-on help?

DemiEmail (opens in a new tab) is the hands-on side: DemiSignal provides ongoing email authentication monitoring, and DemiEmail handles scoped technical work. It configures or troubleshoots SPF, DKIM and DMARC across the services sending email for a business, from a sending-service and DNS review to verification and a documented handover. The work, required access, deliverables and price are agreed as the scope, so you know what it costs before the work begins.

Check your record

DemiSignal's check reads the public DNS records of the domain you enter, with no account needed. For SPF, it flags a missing record, a rule that lets anyone send (+all) or decides nothing (?all), a soft fail (~all), and a record that is close to or over the 10 DNS lookup limit.

Sources

Tools for this

Frequently asked questions

What is an SPF record with a hard fail?

An SPF record that ends in -all. Mail from a server the record does not list gets an SPF fail, an explicit statement that the server is not authorized, and receivers may reject it.

Should I use ~all or -all?

Google recommends ~all. Microsoft recommends -all for Microsoft 365 domains, together with DKIM and DMARC. RFC 9989 warns that -all could get a message rejected before DMARC is checked, even one that would pass DMARC through an aligned DKIM signature.

What SPF record should a domain that sends no email publish?

Microsoft's example for domains not used for email is v=spf1 -all, which authorizes no one to send. Each subdomain needs its own SPF record.

Check your domain now

See the SPF, DKIM and DMARC records your domain publishes and what to fix first. Free, no account needed.