Skip to content
warn

SPF record has no all mechanism — why unmatched senders get a free pass

The all mechanism is what gives an SPF record teeth. Without it, any sender not explicitly listed produces a Neutral result, and RFC 7208 tells receivers to treat Neutral the same as no policy at all.

You get the maintenance burden of SPF with almost none of the protection.

How to fix it

  1. 1Append ~all to the end of the record to start marking unlisted senders as softfail.
  2. 2Monitor DMARC aggregate reports, if you collect them, for legitimate senders you missed.
  3. 3Move to -all once the list is complete.

Check whether your domain has this problem

Free, no signup, about two seconds. You get the exact record to paste.

Related guides