Skip to content
SPF

SPF +all, ?all or no all: how to fix it

An SPF record ending in +all lets anyone send as you; ?all or no all says nothing. How to end the record with ~all or -all safely.

By the Domain Health Hub team · Updated

In short
  • The all at the end of an SPF record says what happens to every server not listed.
  • +all passes everyone, ?all and a missing all say nothing, so the record protects nobody.
  • End with ~all while you confirm the list, then -all.

What it means

An SPF record is a list of senders followed by a catch-all. The qualifier in front of all decides the result for every server not on the list (RFC 7208, section 5.1):

-all
Fail: unlisted servers aren't allowed. The strictest.
~all
Softfail: probably not allowed. Accepted, but treated with suspicion.
?all
Neutral: no opinion. The same as having no SPF for those servers.
+all all
Pass: every server in the world is allowed.
(none)
With no all and no redirect, unlisted servers get neutral.

Why it matters

+all is the serious one: it tells receivers that any server, including a spammer's, is authorised to send as the domain, and SPF then passes for forged mail. Because DMARC accepts an SPF pass, it can help forged email through. ?all and a missing all are less dangerous but leave the record doing nothing useful, and spam filters notice.

Fixing it

  1. Make sure every service that sends as the domain is listed. Look at DMARC reports if you have them: they show every server sending as the domain and whether it passed.
  2. Change the end of the record to ~all. Remove any +all or bare all; there must be only one.
  3. After a couple of weeks with no genuine mail failing, change ~all to -all.
example.com TXT
v=spf1 include:spf.protection.outlook.com ~all

Microsoft 365 and Google Workspace

Microsoft's suggested record ends in -all; Google suggests ~all. Either is fine. Both are far better than the +all some older hosting guides recommended to “stop email bouncing”.

Questions

Is ~all good enough?

With DMARC at quarantine or reject, yes in practice: DMARC decides what happens, and ~all still fails SPF for unlisted servers. -all is tidier and some filters prefer it.

My record ends in redirect= with no all. Is that wrong?

No. The record it redirects to supplies the all. We only flag a missing all when there's no redirect.

Hear about it the day it breaks.

Daily checks on every client domain, alerts when something changes, and a monthly report card your clients will understand.

Start 28-day free trial