SPF +all, ?all or no all: how to fix it
An SPF record ending in +all lets anyone send as you; ?all or no all says nothing. How to end the record with ~all or -all safely.
By the Domain Health Hub team · Updated
- The all at the end of an SPF record says what happens to every server not listed.
- +all passes everyone, ?all and a missing all say nothing, so the record protects nobody.
- End with ~all while you confirm the list, then -all.
What it means
An SPF record is a list of senders followed by a catch-all. The qualifier in front of all decides the result for every server not on the list (RFC 7208, section 5.1):
- -all
- Fail: unlisted servers aren't allowed. The strictest.
- ~all
- Softfail: probably not allowed. Accepted, but treated with suspicion.
- ?all
- Neutral: no opinion. The same as having no SPF for those servers.
- +all all
- Pass: every server in the world is allowed.
- (none)
- With no all and no redirect, unlisted servers get neutral.
Why it matters
+all is the serious one: it tells receivers that any server, including a spammer's, is authorised to send as the domain, and SPF then passes for forged mail. Because DMARC accepts an SPF pass, it can help forged email through. ?all and a missing all are less dangerous but leave the record doing nothing useful, and spam filters notice.
Fixing it
- Make sure every service that sends as the domain is listed. Look at DMARC reports if you have them: they show every server sending as the domain and whether it passed.
- Change the end of the record to
~all. Remove any+allor bareall; there must be only one. - After a couple of weeks with no genuine mail failing, change
~allto-all.
v=spf1 include:spf.protection.outlook.com ~all
Microsoft 365 and Google Workspace
Microsoft's suggested record ends in -all; Google suggests ~all. Either is fine. Both are far better than the +all some older hosting guides recommended to “stop email bouncing”.
Questions
Is ~all good enough?
With DMARC at quarantine or reject, yes in practice: DMARC decides what happens, and ~all still fails SPF for unlisted servers. -all is tidier and some filters prefer it.
My record ends in redirect= with no all. Is that wrong?
No. The record it redirects to supplies the all. We only flag a missing all when there's no redirect.
Hear about it the day it breaks.
Daily checks on every client domain, alerts when something changes, and a monthly report card your clients will understand.