SPF record has no all mechanism — why unmatched senders get a free pass
The all mechanism is what gives an SPF record teeth. Without it, any sender not explicitly listed produces a Neutral result, and RFC 7208 tells receivers to treat Neutral the same as no policy at all.
You get the maintenance burden of SPF with almost none of the protection.
How to fix it
- 1Append ~all to the end of the record to start marking unlisted senders as softfail.
- 2Monitor DMARC aggregate reports, if you collect them, for legitimate senders you missed.
- 3Move to -all once the list is complete.
Check whether your domain has this problem
Free, no signup, about two seconds. You get the exact record to paste.
Related guides
- DKIM record with empty p= — a revoked key still in use
- SPF include points at a domain with no SPF record — a silent PermError
- DMARC record syntax errors that make receivers skip your policy
- DMARC external destination not authorized — why you receive no reports
- Two DMARC records at _dmarc — why your policy is being ignored